
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21584 is a High severity Improper Authorization vulnerability (CWE-285) affecting Atlassian Bamboo Data Center. It was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0, with affected ranges spanning 10.0.0–10.0.3, 10.1.0–10.1.1, 10.2.0–10.2.21, 11.0.0–11.0.8, 12.0.0–12.0.2, and 12.1.0–12.1.9. The vulnerability was disclosed on August 18, 2026, and was reported through Atlassian's Penetration Testing program. It carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 7.6 (High) (Atlassian Advisory, GitHub Advisory).
The vulnerability is classified as CWE-285 (Improper Authorization), meaning the product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action. An authenticated attacker with low privileges can exploit this flaw over the network without user interaction to gain unintended access to restricted resources or functionality within Bamboo Data Center. The CVSS v4.0 Attack Requirements metric is rated "Present," indicating that specific deployment or execution conditions must exist for exploitation, slightly raising the bar for attackers. No public proof-of-concept code or detailed technical write-up has been published as of the disclosure date (GitHub Advisory, Atlassian Advisory).
Successful exploitation allows an authenticated attacker to bypass authorization controls and access resources or functionality beyond their permitted scope, resulting in high confidentiality and high integrity impact with no availability impact. This could expose sensitive build pipeline data, credentials, source code configurations, or other restricted information stored within Bamboo Data Center, and may potentially enable arbitrary code execution. The vulnerability is scoped to the vulnerable system itself, with no direct impact on subsequent systems, though access to CI/CD pipeline data could facilitate lateral movement within an organization's development infrastructure (GitHub Advisory, Atlassian Advisory).
As of the disclosure date, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation (GitHub Advisory). No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.324% (25th percentile), indicating a low near-term probability of exploitation. Exploitation requires valid authentication credentials, which limits opportunistic mass exploitation but does not preclude targeted attacks by insiders or attackers with compromised accounts.
Atlassian recommends upgrading Bamboo Data Center to a patched version immediately. The fixed versions are 10.2.22 (for the 10.2 LTS branch) and 12.1.10 (for the 12.1 LTS branch); users on other affected versions (10.0.x, 10.1.x, 11.0.x, 12.0.x) should upgrade to the latest available release. No configuration-based workaround has been published; until patching is feasible, Atlassian advises monitoring user access logs for unauthorized resource access attempts and restricting network access to Bamboo Data Center instances to trusted networks only (Atlassian Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."