← Vulnerability feed

Vulnerability record · CVE-2026-21569 · published 28 January 2026

CVE-2026-21569: Atlassian crowd xml external entity (xxe) vulnerability

Atlassian · Crowd

This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server. This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.9, allows an authenticated attacker to access local and remote content which has high impact to confidentiality, low impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Crowd Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Crowd Data Center and Server 7.1: Upgrade to a release greater than or equal to 7.1.3 See the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center and Server from the download center (https://www.atlassian.com/software/crowd/download-archive). This vulnerability was reported via our Atlassian (Internal) program.

7.9 CVSS 3.0 High EPSS 0.33% · top 75.8% CWE-611 · XML external entity (XXE)
7.9CVSS 3.0 base score
0.33%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server. This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.9, allows an authenticated attacker to access local and remote content which has high impact to confidentiality, low impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Crowd Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Crowd Data Center and Server 7.1: Upgrade to a release greater than or equal to 7.1.3 See the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center and Server from the download center (https://www.atlassian.com/software/crowd/download-archive). This vulnerability was reported via our Atlassian (Internal) program.

CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-21569 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-11580Atlassian Crowd pdkinstall plugin allows unauthenticated remote code executionAtlassian Crowd and Crowd Data Center shipped release builds with the pdkinstall development plugin incorrectly enabled. An attacker who can reach th…KEVEPSS 95%analysed9.8CVE-2022-43782Atlassian crowd vulnerabilityAffected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability …EPSS 0.95%9.8CVE-2022-26136Atlassian bamboo improper authentication vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps…EPSS 5.4%9.8CVE-2016-6496Atlassian crowd improper input validation vulnerabilityThe LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP att…EPSS 4.7%9.1CVE-2012-2926Atlassian JIRA and related products XML parser file read and DoSMultiple Atlassian products (JIRA, Confluence, FishEye, Crucible, Bamboo, Crowd) fail to properly restrict the capabilities of third-party XML parser…EPSS 66%analysed8.8CVE-2023-22521Atlassian crowd vulnerabilityThis High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.6 of Crowd Data Center and Server. This RCE (Remote Code E…EPSS 1.2%8.8CVE-2022-26137Atlassian bamboo origin validation error vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the a…EPSS 2.3%8.1CVE-2017-18105Atlassian crowd vulnerabilityThe console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have prev…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2026-21569), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.