A security update has been released following the discovery of CVE-2026-21582, an authentication and session management vulnerability in Atlassian products.
The affected products are Crowd Data Center, Jira Software Data Center, and Jira Service Management Data Center.
The affected versions are as follows:
Crowd Data Center: 7.2.1.
Jira Service Management Data Center: 10.3.0 Through 10.3.23, 11.3.0 Through 11.3.8.
Jira Software Data Center: 9.12.14 Through 9.12.37, 10.3.0 Through 10.3.23, 11.3.0 Through 11.3.8.
This vulnerability is described as a BASM (Broken Authentication & Session Management) vulnerability.
The latest version containing patches is as follows:
Crowd Data Center: 7.2.2 Or later.
Jira Service Management Data Center: 10.3.24 Or later, 11.3.10 Or later.
Jira Software Data Center: 9.12.38 Or later, 10.3.24 Or later, 11.3.10 Or later.
Atlassian has advised users to update to the latest version with the Vulnerability Patch, following the instructions on the reference site.