Atlassian Product Security Update Advisory (CVE-2026-21582)

Atlassian Product Security Update Advisory (CVE-2026-21582)
  • A security update has been released following the discovery of CVE-2026-21582, an authentication and session management vulnerability in Atlassian products.
  • The affected products are Crowd Data Center, Jira Software Data Center, and Jira Service Management Data Center.
  • The affected versions are as follows:
    • Crowd Data Center: 7.2.1.
    • Jira Service Management Data Center: 10.3.0 Through 10.3.23, 11.3.0 Through 11.3.8.
    • Jira Software Data Center: 9.12.14 Through 9.12.37, 10.3.0 Through 10.3.23, 11.3.0 Through 11.3.8.
  • This vulnerability is described as a BASM (Broken Authentication & Session Management) vulnerability.
  • The latest version containing patches is as follows:
    • Crowd Data Center: 7.2.2 Or later.
    • Jira Service Management Data Center: 10.3.24 Or later, 11.3.10 Or later.
    • Jira Software Data Center: 9.12.38 Or later, 10.3.24 Or later, 11.3.10 Or later.
  • Atlassian has advised users to update to the latest version with the Vulnerability Patch, following the instructions on the reference site.