Description
This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center.

This BASM (Broken Authentication & Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as another user.

Atlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:

Crowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2



See the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center from the download center (https://www.atlassian.com/software/crowd/download-archive).

This vulnerability was reported via our Penetration Testing program.
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability, assigned CVE-2026-21582, allows an attacker who is not authenticated to impersonate any user in Atlassian Crowd Data Center. The flaw is a classic broken authentication and session management weakness that results in unauthorized execution of actions with the privileges of the victim user. The impact is full privilege escalation; an attacker can perform any operation the compromised account is permitted to do, potentially accessing confidential data or altering system configuration.

Affected Systems

Atlassian Crowd Data Center version 7.2.1 is affected. Atlassian recommends upgrading to version 7.2.2 or later where the issue is fixed. No other versions were listed as affected.

Risk and Exploitability

The CVSS score of 8.8 reflects a high severity of the vulnerability. Exploitation requires no authentication, implying that the attack surface is potentially broad. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is any entity able to send requests to the Crowd server, such as internal network traffic or an external attacker with network access if the application is exposed.

Generated by OpenCVE AI on August 19, 2026 at 09:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Crowd Data Center to a version greater than or equal to 7.2.2
  • If immediate upgrade is not possible, plan a phased migration to a supported release that includes the fix
  • Monitor authentication logs for unusual activity to detect potential exploitation attempts

Generated by OpenCVE AI on August 19, 2026 at 09:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Atlassian
Atlassian crowd Data Center
Vendors & Products Atlassian
Atlassian crowd Data Center

Wed, 19 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated User Impersonation in Atlassian Crowd Data Center
Weaknesses CWE-287

Tue, 18 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center. This BASM (Broken Authentication & Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as another user. Atlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Crowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2 See the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center from the download center (https://www.atlassian.com/software/crowd/download-archive). This vulnerability was reported via our Penetration Testing program.
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Atlassian Crowd Data Center
cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published:

Updated: 2026-08-20T18:34:02.178Z

Reserved: 2026-01-01T00:00:40.721Z

Link: CVE-2026-21582

cve-icon Vulnrichment

Updated: 2026-08-20T18:30:40.946Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T22:16:50.340

Modified: 2026-08-26T16:46:22.330

Link: CVE-2026-21582

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T13:30:04Z

Weaknesses