PT-2026-25921 · Atlassian · Bamboo

·

CVE-2026-21570

·

Published

2026-03-17

·

Updated

2026-08-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bamboo Data Center versions 9.6.0 through 9.6.23 Bamboo Data Center versions 10.0.0 through 10.2.15 Bamboo Data Center versions 11.0.0 through 11.1.0 Bamboo Data Center versions 12.0.0 through 12.1.2
Description An issue exists that allows an authenticated attacker to perform Remote Code Execution (RCE), which is the ability to execute malicious code on a remote system.
Recommendations Upgrade Bamboo Data Center 9.6 to version 9.6.24 or later. Upgrade Bamboo Data Center 10.2 to version 10.2.16 or later. Upgrade Bamboo Data Center 12.1 to version 12.1.3 or later.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-21570

Affected Products

Bamboo