PT-2026-34015 · Atlassian · Bamboo

CVE-2026-21571

·

Published

2026-04-21

·

Updated

2026-08-10

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Bamboo Data Center versions 9.6.0 through 9.6.24 Bamboo Data Center versions 10.0.0 through 10.2.17 Bamboo Data Center versions 11.0.0 through 11.1.0 Bamboo Data Center versions 12.0.0 through 12.1.5
Description An OS Command Injection issue exists that allows an authenticated attacker to achieve Remote Code Execution (RCE) on the remote system. This flaw enables the execution of arbitrary commands without requiring user interaction, potentially leading to full server compromise and high impact on confidentiality, integrity, and availability. Attackers may use this to hijack build pipelines within the CI/CD infrastructure.
Recommendations Upgrade Bamboo Data Center version 9.6.0 to a release greater than or equal to 9.6.25. Upgrade Bamboo Data Center version 10.2 to a release greater than or equal to 10.2.18. Upgrade Bamboo Data Center version 12.1 to a release greater than or equal to 12.1.6.

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-21571

Affected Products

Bamboo