Description
This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center.

This Improper Authorization vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code.

Atlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:

* Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.22

* Bamboo Data Center 12.1: Upgrade to a release greater than or equal to 12.1.10



See the release notes (https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html). You can download the latest version of Bamboo Data Center from the download center (https://www.atlassian.com/software/bamboo/download-archives).

This vulnerability was reported via our Penetration Testing program.
Published: 2026-08-18
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an Improper Authorization flaw in Atlassian Bamboo Data Center versions 10 through 12. An attacker with valid credentials can elevate privileges to access resources or functions not intended for them. The flaw could allow exposure of sensitive information and, in some scenarios, enable execution of arbitrary code. With a CVSS score of 7.6, the issue is classified as high severity.

Affected Systems

Affected products include Atlassian Bamboo Data Center, specifically versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0. Atlassian recommends upgrading to a release that is greater than or equal to 10.2.22 for Bamboo 10.2 or greater than or equal to 12.1.10 for Bamboo 12.1, or to the latest available release.

Risk and Exploitability

It is exploitable only by an authenticated user, so it requires a valid login. No information indicates availability of remote exploitation tools or existing public exploits. The EPSS score is indicated as < 1%, implying a very low exploitation probability, and the issue is not listed in CISA’s KEV catalog. The CVSS score of 7.6 reflects a high risk of unauthorized data access or code execution, but the attack vector is not remotely exploitable without prior authentication. Overall, the threat remains significant for organizations that cannot promptly apply the recommended patch.

Generated by OpenCVE AI on August 28, 2026 at 22:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Bamboo Data Center to the latest patch or to a release equal to or newer than 10.2.22 for Bamboo 10.2 or 12.1.10 for Bamboo 12.1.
  • If a full upgrade cannot be performed immediately, upgrade to one of the supported fixed releases listed above to eliminate the vulnerability.
  • Review and tighten role‑based access controls to ensure that authenticated users have only the permissions they require, and monitor logs for unauthorized access attempts.

Generated by OpenCVE AI on August 28, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Atlassian bamboo
CPEs cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:*
Vendors & Products Atlassian bamboo
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Fri, 28 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Atlassian Bamboo Data Center Allowing Privilege Escalation

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allowing Unintended Access and Potential Code Execution in Atlassian Bamboo Data Center
Weaknesses CWE-284

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Atlassian
Atlassian bamboo Data Center
Vendors & Products Atlassian
Atlassian bamboo Data Center

Wed, 19 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allowing Unintended Access and Potential Code Execution in Atlassian Bamboo Data Center
Weaknesses CWE-284

Tue, 18 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. Atlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.22 * Bamboo Data Center 12.1: Upgrade to a release greater than or equal to 12.1.10 See the release notes (https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html). You can download the latest version of Bamboo Data Center from the download center (https://www.atlassian.com/software/bamboo/download-archives). This vulnerability was reported via our Penetration Testing program.
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Atlassian Bamboo Bamboo Data Center
cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published:

Updated: 2026-08-28T15:04:12.086Z

Reserved: 2026-01-01T00:00:40.721Z

Link: CVE-2026-21584

cve-icon Vulnrichment

Updated: 2026-08-20T18:31:22.080Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T22:16:50.460

Modified: 2026-09-02T00:11:20.300

Link: CVE-2026-21584

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T22:45:05Z

Weaknesses