Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-21582

Gravedad CVSS v4.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
18/08/2026
Última modificación:
18/08/2026

Descripción

*** Pendiente de traducción *** This High severity BASM (Broken Authentication &amp; Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center.<br /> <br /> This BASM (Broken Authentication &amp; Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as another user.<br /> <br /> Atlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:<br /> <br /> Crowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2<br /> <br /> <br /> <br /> See the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center from the download center (https://www.atlassian.com/software/crowd/download-archive). <br /> <br /> This vulnerability was reported via our Penetration Testing program.