Atlassian Product Security Update Advisory (CVE-2026-21569)
Overview
We have released security updates to fix vulnerabilities in Atlassian products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2026-21569
Crowd Data Center and Server Versions: 7.1.0 or later and 7.1.2 or earlier
Crowd Data Center and Server Versions: 6.3.0 or later and 6.3.3 or earlier
Resolved Vulnerabilities
XML external entity injection vulnerability in Crowd Data Center and Server (CVE-2026-21569)
Vulnerability Patches
Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2026-21569
Crowd Data Center Version: 7.1.3
Crowd Data Center version: 6.3.4
References
[1] Security Bulletin – January 20 2026
https://confluence.atlassian.com/security/security-bulletin-january-20-2026-1712324819.html
[2] XXE (XML External Entity Injection) in Crowd Data Center and Server
https://jira.atlassian.com/browse/CWD-6453