Vulnerability record · CVE-2012-2926 · published 22 May 2012
CVE-2012-2926: Atlassian JIRA and related products XML parser file read and DoS
Atlassian · Bamboo
Multiple Atlassian products (JIRA, Confluence, FishEye, Crucible, Bamboo, Crowd) fail to properly restrict the capabilities of third-party XML parsers. This lets remote attackers read arbitrary files or exhaust resources for denial of service. The flaw affects a broad set of widely deployed collaboration and issue-tracking servers.
Description
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Automated analysis
critical priorityCVSS 3.1 base score is 9.1 (critical) with high confidentiality and availability impact and no authentication required, and EPSS is in the 99th percentile.
What it is
Multiple Atlassian products (JIRA, Confluence, FishEye, Crucible, Bamboo, Crowd) fail to properly restrict the capabilities of third-party XML parsers. This lets remote attackers read arbitrary files or exhaust resources for denial of service. The flaw affects a broad set of widely deployed collaboration and issue-tracking servers.
Impact
An attacker can read arbitrary files on the server, potentially exposing credentials and configuration, or consume resources to cause a denial of service.
Attack surface
Reachable remotely over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The specific request paths are not detailed in the record.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is 0.66578 (99.25th percentile), indicating elevated predicted exploitation likelihood.
What to do
- Upgrade to the fixed versions listed in the Atlassian advisories: JIRA 5.0.1, Confluence 3.5.16/4.0.7/4.1.10, FishEye and Crucible 2.5.8/2.6.8/2.7.12, Bamboo 3.3.4/3.4.5, Crowd 2.0.9/2.1.2/2.2.9/2.3.7/2.4.1.
- Apply the vendor security advisories dated 2012-05-17 referenced in the record.
- Restrict network access to these Atlassian services to trusted users and networks where feasible.
- Monitor and cap resource usage on affected servers to limit denial-of-service impact.
Detection
- Review server logs for anomalous XML parsing requests or unexpected file access patterns.
- Monitor for spikes in CPU, memory or request volume consistent with resource-exhaustion attempts.
- Audit file access on hosts running affected Atlassian products for reads of sensitive files by the application process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-2926 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-2926), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.