CVE-2026-21569
7.9Atlassian · Crowd Data Center and Server
Atlassian Crowd Data Center and Server is affected by an XML External Entity (XXE) injection vulnerability, allowing authenticated attackers to access local and remote content.
Executive summary
An authenticated XML External Entity (XXE) vulnerability in Atlassian Crowd Data Center and Server poses a high risk to system confidentiality and availability.
Vulnerability
This vulnerability is an XML External Entity (XXE) injection flaw occurring in the processing of XML input. It requires the attacker to possess authenticated access to the system to trigger the vulnerability.
Business impact
The exploitation of this XXE vulnerability carries a CVSS score of 7.9, reflecting its potential to compromise sensitive data and disrupt service availability. An attacker can leverage this flaw to access local files or trigger unauthorized remote requests, leading to significant information disclosure and potential denial of service scenarios. Given the high impact on confidentiality and availability, this issue requires prompt attention to protect the integrity of the application environment.
Remediation
Immediate Action: Administrators must upgrade Atlassian Crowd Data Center and Server to version 7.1.3 or later to remediate the vulnerability.
Proactive Monitoring: Security teams should monitor system access logs for unusual XML processing patterns or requests directed toward sensitive local system files.
Compensating Controls: If immediate patching is not feasible, implement strict input validation on XML parsers and ensure that the application is running with the least privilege necessary to restrict the impact of potential file access.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The vulnerability represents a clear risk to the security of the Atlassian Crowd environment. Organizations running versions 7.1.0 through 7.1.2 should prioritize upgrading to version 7.1.3 as part of their next maintenance cycle to eliminate this exposure. Failure to patch may allow authenticated users to gain unauthorized access to system-level data, which could be escalated for further malicious activity.