CVE-2026-21584
Bamboo vulnerability analysis and mitigation

Overview

CVE-2026-21584 is a High severity Improper Authorization vulnerability (CWE-285) affecting Atlassian Bamboo Data Center. It was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0, with affected ranges spanning 10.0.0–10.0.3, 10.1.0–10.1.1, 10.2.0–10.2.21, 11.0.0–11.0.8, 12.0.0–12.0.2, and 12.1.0–12.1.9. The vulnerability was disclosed on August 18, 2026, and was reported through Atlassian's Penetration Testing program. It carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 7.6 (High) (Atlassian Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-285 (Improper Authorization), meaning the product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action. An authenticated attacker with low privileges can exploit this flaw over the network without user interaction to gain unintended access to restricted resources or functionality within Bamboo Data Center. The CVSS v4.0 Attack Requirements metric is rated "Present," indicating that specific deployment or execution conditions must exist for exploitation, slightly raising the bar for attackers. No public proof-of-concept code or detailed technical write-up has been published as of the disclosure date (GitHub Advisory, Atlassian Advisory).

Impact

Successful exploitation allows an authenticated attacker to bypass authorization controls and access resources or functionality beyond their permitted scope, resulting in high confidentiality and high integrity impact with no availability impact. This could expose sensitive build pipeline data, credentials, source code configurations, or other restricted information stored within Bamboo Data Center, and may potentially enable arbitrary code execution. The vulnerability is scoped to the vulnerable system itself, with no direct impact on subsequent systems, though access to CI/CD pipeline data could facilitate lateral movement within an organization's development infrastructure (GitHub Advisory, Atlassian Advisory).

Exploitability

As of the disclosure date, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation (GitHub Advisory). No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.324% (25th percentile), indicating a low near-term probability of exploitation. Exploitation requires valid authentication credentials, which limits opportunistic mass exploitation but does not preclude targeted attacks by insiders or attackers with compromised accounts.

Mitigation and workarounds

Atlassian recommends upgrading Bamboo Data Center to a patched version immediately. The fixed versions are 10.2.22 (for the 10.2 LTS branch) and 12.1.10 (for the 12.1 LTS branch); users on other affected versions (10.0.x, 10.1.x, 11.0.x, 12.0.x) should upgrade to the latest available release. No configuration-based workaround has been published; until patching is feasible, Atlassian advises monitoring user access logs for unauthorized resource access attempts and restricting network access to Bamboo Data Center instances to trusted networks only (Atlassian Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Bamboo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-21571CRITICAL9.4
  • Bamboo logoBamboo
  • bamboo
NoYesApr 21, 2026
CVE-2026-21570HIGH8.6
  • Bamboo logoBamboo
  • cpe:2.3:a:atlassian:bamboo
NoYesMar 17, 2026
CVE-2024-21687HIGH8.1
  • Bamboo logoBamboo
  • cpe:2.3:a:atlassian:bamboo
NoYesJul 16, 2024
CVE-2024-21689HIGH8
  • Bamboo logoBamboo
  • bamboo
NoYesAug 20, 2024
CVE-2026-21584HIGH7.6
  • Bamboo logoBamboo
  • bamboo
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management