CVE-2026-21584: 
Bamboo Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-21584 is a High severity Improper Authorization vulnerability (CWE-285) affecting Atlassian Bamboo Data Center. It was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0, with affected ranges spanning 10.0.0–10.0.3, 10.1.0–10.1.1, 10.2.0–10.2.21, 11.0.0–11.0.8, 12.0.0–12.0.2, and 12.1.0–12.1.9. The vulnerability was disclosed on August 18, 2026, and was reported through Atlassian's Penetration Testing program. It carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 7.6 (High) (Atlassian Advisory, GitHub Advisory).

Détails techniques

The vulnerability is classified as CWE-285 (Improper Authorization), meaning the product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action. An authenticated attacker with low privileges can exploit this flaw over the network without user interaction to gain unintended access to restricted resources or functionality within Bamboo Data Center. The CVSS v4.0 Attack Requirements metric is rated "Present," indicating that specific deployment or execution conditions must exist for exploitation, slightly raising the bar for attackers. No public proof-of-concept code or detailed technical write-up has been published as of the disclosure date (GitHub Advisory, Atlassian Advisory).

Impact

Successful exploitation allows an authenticated attacker to bypass authorization controls and access resources or functionality beyond their permitted scope, resulting in high confidentiality and high integrity impact with no availability impact. This could expose sensitive build pipeline data, credentials, source code configurations, or other restricted information stored within Bamboo Data Center, and may potentially enable arbitrary code execution. The vulnerability is scoped to the vulnerable system itself, with no direct impact on subsequent systems, though access to CI/CD pipeline data could facilitate lateral movement within an organization's development infrastructure (GitHub Advisory, Atlassian Advisory).

Exploitabilité

As of the disclosure date, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation (GitHub Advisory). No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.324% (25th percentile), indicating a low near-term probability of exploitation. Exploitation requires valid authentication credentials, which limits opportunistic mass exploitation but does not preclude targeted attacks by insiders or attackers with compromised accounts.

Atténuation et solutions de contournement

Atlassian recommends upgrading Bamboo Data Center to a patched version immediately. The fixed versions are 10.2.22 (for the 10.2 LTS branch) and 12.1.10 (for the 12.1 LTS branch); users on other affected versions (10.0.x, 10.1.x, 11.0.x, 12.0.x) should upgrade to the latest available release. No configuration-based workaround has been published; until patching is feasible, Atlassian advises monitoring user access logs for unauthorized resource access attempts and restricting network access to Bamboo Data Center instances to trusted networks only (Atlassian Advisory, GitHub Advisory).

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Bamboo Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-21571CRITICAL9.4
  • Bamboo logoBamboo
  • bamboo
NonOuiApr 21, 2026
CVE-2026-21589CRITICAL9.3
  • Bamboo logoBamboo
  • cpe:2.3:a:atlassian:jira_service_management
NonOuiOct 05, 2026
CVE-2026-21570HIGH8.6
  • Bamboo logoBamboo
  • cpe:2.3:a:atlassian:bamboo
NonOuiMar 17, 2026
CVE-2024-21689HIGH8
  • Bamboo logoBamboo
  • cpe:2.3:a:atlassian:bamboo
NonOuiAug 20, 2024
CVE-2026-21584HIGH7.6
  • Bamboo logoBamboo
  • bamboo
NonOuiAug 18, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités