CVE-2026-21569
Atlassian Crowd vulnerability analysis and mitigation

This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server.


This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.9, allows an authenticated attacker to access local and remote content which has high impact to confidentiality, low impact to integrity, high impact to availability, and requires no user interaction. 

Atlassian recommends that Crowd Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:

	* Crowd Data Center and Server 7.1: Upgrade to a release greater than or equal to 7.1.3



See the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center and Server from the download center (https://www.atlassian.com/software/crowd/download-archive). 

This vulnerability was reported via our Atlassian (Internal) program.

SourceNVD

Related Atlassian Crowd vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-43782CRITICAL9.8
  • Atlassian CrowdAtlassian Crowd
  • cpe:2.3:a:atlassian:crowd
NoYesNov 17, 2022
CVE-2022-26136CRITICAL9.8
  • BambooBamboo
  • cpe:2.3:a:atlassian:jira_service_desk
NoYesJul 20, 2022
CVE-2023-22521HIGH8.8
  • Atlassian CrowdAtlassian Crowd
  • cpe:2.3:a:atlassian:crowd
NoYesNov 21, 2023
CVE-2022-26137HIGH8.8
  • BambooBamboo
  • cpe:2.3:a:atlassian:jira_service_desk
NoYesJul 20, 2022
CVE-2026-21569HIGH7.9
  • Atlassian CrowdAtlassian Crowd
  • cpe:2.3:a:atlassian:crowd
NoYesJan 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management