← Vulnerability feed

Vulnerability record · CVE-2012-2926 · published 22 May 2012

CVE-2012-2926: Atlassian JIRA and related products XML parser file read and DoS

Atlassian · Bamboo

Multiple Atlassian products (JIRA, Confluence, FishEye, Crucible, Bamboo, Crowd) fail to properly restrict the capabilities of third-party XML parsers. This lets remote attackers read arbitrary files or exhaust resources for denial of service. The flaw affects a broad set of widely deployed collaboration and issue-tracking servers.

9.1 CVSS 3.1 Critical EPSS 66% · top 0.7%
9.1CVSS 3.1 base score, v2 6.4
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 3.1 base score is 9.1 (critical) with high confidentiality and availability impact and no authentication required, and EPSS is in the 99th percentile.

What it is

Multiple Atlassian products (JIRA, Confluence, FishEye, Crucible, Bamboo, Crowd) fail to properly restrict the capabilities of third-party XML parsers. This lets remote attackers read arbitrary files or exhaust resources for denial of service. The flaw affects a broad set of widely deployed collaboration and issue-tracking servers.

Impact

An attacker can read arbitrary files on the server, potentially exposing credentials and configuration, or consume resources to cause a denial of service.

Attack surface

Reachable remotely over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The specific request paths are not detailed in the record.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged, but EPSS is 0.66578 (99.25th percentile), indicating elevated predicted exploitation likelihood.

What to do

  • Upgrade to the fixed versions listed in the Atlassian advisories: JIRA 5.0.1, Confluence 3.5.16/4.0.7/4.1.10, FishEye and Crucible 2.5.8/2.6.8/2.7.12, Bamboo 3.3.4/3.4.5, Crowd 2.0.9/2.1.2/2.2.9/2.3.7/2.4.1.
  • Apply the vendor security advisories dated 2012-05-17 referenced in the record.
  • Restrict network access to these Atlassian services to trusted users and networks where feasible.
  • Monitor and cap resource usage on affected servers to limit denial-of-service impact.

Detection

  • Review server logs for anomalous XML parsing requests or unexpected file access patterns.
  • Monitor for spikes in CPU, memory or request volume consistent with resource-exhaustion attempts.
  • Audit file access on hosts running affected Atlassian products for reads of sensitive files by the application process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://confluence.atlassian.com/display/BAMBOO/Bamboo+Security+Advisory+2012-05-17 PatchVendor Advisory
http://confluence.atlassian.com/display/CROWD/Crowd+Security+Advisory+2012-05-17 PatchVendor Advisory
http://confluence.atlassian.com/display/DOC/Confluence+Security+Advisory+2012-05-17 PatchVendor Advisory
http://confluence.atlassian.com/display/FISHEYE/FishEye+and+Crucible+Security+Advisory+2012-05-17 PatchVendor Advisory
http://confluence.atlassian.com/display/JIRA/JIRA+Security+Advisory+2012-05-17 PatchVendor Advisory
http://osvdb.org/81993 Broken Link
http://secunia.com/advisories/49146 Not Applicable
http://www.securityfocus.com/bid/53595 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/75682 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/75697 Third Party AdvisoryVDB Entry
http://confluence.atlassian.com/display/BAMBOO/Bamboo+Security+Advisory+2012-05-17 PatchVendor Advisory
http://confluence.atlassian.com/display/CROWD/Crowd+Security+Advisory+2012-05-17 PatchVendor Advisory
http://confluence.atlassian.com/display/DOC/Confluence+Security+Advisory+2012-05-17 PatchVendor Advisory
http://confluence.atlassian.com/display/FISHEYE/FishEye+and+Crucible+Security+Advisory+2012-05-17 PatchVendor Advisory
http://confluence.atlassian.com/display/JIRA/JIRA+Security+Advisory+2012-05-17 PatchVendor Advisory
http://osvdb.org/81993 Broken Link
http://secunia.com/advisories/49146 Not Applicable
http://www.securityfocus.com/bid/53595 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/75682 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/75697 Third Party AdvisoryVDB Entry

Track CVE-2012-2926 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-22527Atlassian Confluence Data Center and Server template injection RCEOlder versions of Confluence Data Center and Server contain a template injection flaw (CWE-74) that lets an unauthenticated attacker execute code on …KEVEPSS 100%analysed9.8CVE-2023-22518Atlassian Confluence improper authorization allows admin account creationConfluence Data Center and Server contain an improper authorization flaw that lets an unauthenticated attacker reset Confluence and create an instanc…KEVEPSS 100%analysed9.8CVE-2023-22515Atlassian Confluence Data Center and Server broken access control allows admin account creationConfluence Data Center and Server contain a broken access control flaw that lets an unauthenticated external attacker create unauthorized administrat…KEVEPSS 99%analysed9.8CVE-2022-26134Atlassian Confluence Server and Data Center OGNL injection RCEConfluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker execute arbitrary code on …KEVEPSS 100%analysed9.8CVE-2021-26084Atlassian Confluence Server and Data Center OGNL injection RCEConfluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker run arbitrary code on the …KEVEPSS 100%analysed9.8CVE-2019-11580Atlassian Crowd pdkinstall plugin allows unauthenticated remote code executionAtlassian Crowd and Crowd Data Center shipped release builds with the pdkinstall development plugin incorrectly enabled. An attacker who can reach th…KEVEPSS 95%analysed9.8CVE-2019-3396Atlassian Confluence Widget Connector path traversal and RCE via SSTIThe Widget Connector macro in Atlassian Confluence Server and Data Center fails to safely handle template input, allowing server-side template inject…KEVEPSS 100%analysed8.8CVE-2019-3398Atlassian Confluence Server path traversal in downloadallattachmentsConfluence Server and Data Center contain a path traversal flaw in the downloadallattachments resource. An attacker with permission to add attachment…KEVEPSS 97%analysed

Source: NIST National Vulnerability Database (record CVE-2012-2926), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.