Atlassian Product Security Update Advisory (CVE-2026-21569)

Atlassian Product Security Update Advisory (CVE-2026-21569)

Overview

 

We have released security updates to fix vulnerabilities in Atlassian products. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2026-21569

 

Crowd Data Center and Server Versions: 7.1.0 or later and 7.1.2 or earlier
Crowd Data Center and Server Versions: 6.3.0 or later and 6.3.3 or earlier

 

 

Resolved Vulnerabilities

 

XML external entity injection vulnerability in Crowd Data Center and Server (CVE-2026-21569)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2026-21569

 

Crowd Data Center Version: 7.1.3
Crowd Data Center version: 6.3.4

 

 

References

 

[1] Security Bulletin – January 20 2026
https://confluence.atlassian.com/security/security-bulletin-january-20-2026-1712324819.html
[2] XXE (XML External Entity Injection) in Crowd Data Center and Server
https://jira.atlassian.com/browse/CWD-6453