CVE-2026-21571Disclosure(atlassian / bamboo)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch atlassian bamboo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center.   This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 9.4 and a CVSS Vector of CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H allows an authenticated attacker to execute commands on the remote system, which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.   Atlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Bamboo Data Center 9.6.0: Upgrade to a release greater than or equal to 9.6.25 Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.18  Bamboo Data Center 12.1: Upgrade to a release greater than or equal to 12.1.6 See the release notes ([https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html]). You can download the latest version of Bamboo Data Center from the download center ([https://www.atlassian.com/software/bamboo/download-archives]).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bamboo

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-04-22); latest day: 1
  • 9 total mentions across 4 days

Affected systems

Vendors
Products
bamboo

Deep dive

Activity timeline9 mentions / 4d
01234Mentions · 2026-04-21: 1Mentions · 2026-04-22: 4Mentions · 2026-04-27: 3Mentions · 2026-04-29: 1Patch / Workaround · 2026-04-22: 2Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 4Technical Details · 2026-04-27: 2Technical Details · 2026-04-29: 104-2104-2204-2704-29
Signal classification3 categories
Disclosure
666.7%
Patch
222.2%
General
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-211
Disclosure1
2026-04-224
Disclosure2Patch2
2026-04-273
Disclosure2General1
2026-04-291
Disclosure1
Full discourse9 posts
  • Gray Hats@the_yellow_fall
    Patch

    Atlassian Bamboo Data Center hit by critical 9.4 RCE (CVE-2026-21571). Attackers can hijack your build pipeline. Secure your supply chain—patch now! #BambooRCE #Atlassian #CyberSecurity #SupplyChain #InfoSec #DevOps #PatchNow https://securityonline.info/atlassian-bamboo-rce-cve-2026-21571-critical-update/ https://t.co/lZXHKwOPYI

    Post summary

    Alert about a critical RCE vulnerability (CVE‑2026‑21571) in Atlassian Bamboo, urging users to apply the latest patch immediately.

    05151596
    12.5K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-21571: OS Command Injection in Atlassian Bamboo Data Center, 9.4 rating 🔥 RCE vulnerability in Atlassian Bamboo Data Center allows an authenticated attacker to execute commands on affected servers. It may cause to full server compromise. 👉 https://nt.ls/KqPWl

    Post summary

    The text announces CVE‑2026‑21571 as an OS command injection leading to RCE in Atlassian Bamboo Data Center, highlighting the risk but providing no PoC, exploit, patch, or evidence of active exploitation.

    02054456
    7.6K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Atlassian Bamboo の脆弱性 CVE-2026-21571/33871  が FIX:リモート・コマンド・インジェクションの恐れ https://iototsecnews.jp/2026/04/22/critical-atlassian-bamboo-data-center-and-server-flaw-enables-command-injection-attacks/ Atlassian Bamboo に、二つの脆弱性が発見されました。一つ目の CVE-2026-21571 は、外部からの入力を適切に処理できず、サーバを操作する命令が実行されてしまう、OS コマンド・インジェクションに起因します。これにより、意図しない操作を許してしまいます。二つ目の CVE-2026-33871 は、製品に組み込まれた外部ライブラリの HTTP/2 処理に問題があり、過度な負荷がかかることで、サービスが止まってしまう恐れがあります。ご利用のチームは、ご注意ください。 #Atlassian #BambooDataCenter #CVE202621571 #CVE202633871 #Vulnerability

    Post summary

    Atlassian Bamboo was reported to have two critical vulnerabilities—CVE-2026-21571, an OS command injection flaw, and CVE-2026-33871, an HTTP/2 processing bug that can crash the service—along with a hint that a fix exists, though specific patch details are not disclosed.

    01000122
    485 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21571 This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data… https://www.cve.org/CVERecord?id=CVE-2026-21571

    Post summary

    This brief announcement notes CVE‑2026‑21571 as a Critical OS Command Injection affecting multiple Bamboo Data releases, with a link to the official CVE record.

    00010209
    57.3K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Atlassian discloses critical CVE-2026-21571 in Bamboo Data Center and Server, CVSS 9.4, enabling authenticated remote OS command execution on unpatched systems. https://threatcluster.io/cluster/critical-os-command-injection-vulnerability-in-atlassian-bam-4f470807

    Post summary

    The text announces the discovery of a critical vulnerability (CVE‑2026‑21571) affecting Atlassian Bamboo with high CVSS, enabling authenticated OS command execution on unpatched systems.

    01000138
    160 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-21571 This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data… https://www.cve.org/CVERecord?id=CVE-2026-21571 ----- Traducción: CVE-2026-21571 Esta… http://infoflow.cloud`

    Post summary

    The article announces CVE‑2026‑21571, an OS Command Injection flaw in Bamboo Data versions 9.6.0–12.1.0 with critical severity, but it does not mention exploits, patches, or active exploitation.

    0000046
    72 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Atlassian ❗ CVE-2026-21571 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-atlassian-3/ https://t.co/FytbW2iu9T

    Post summary

    The post announces a vulnerability in Atlassian products (CVE-2026-21571) and directs readers to external links for more information.

    00000136
    6.7K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Patch

    🚨 Critical #CVE-2026-21571: 94 CVSS Bamboo Command Injection Flaw – Patch NOW Before Attackers Own Your CI/CD Pipeline + Video https://undercodetesting.com/critical-cve-2026-21571-94-cvss-bamboo-command-injection-flaw-patch-now-before-attackers-own-your-ci-cd-pipeline-video/ Educational Purposes!

    Post summary

    The message is a warning about CVE-2026-21571, a critical Bamboo command injection flaw with a 94 CVSS score, urging users to apply a patch immediately, and is supported by a video demonstration.

    0000053
    497 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-21571: Atlassian (CVSS: 9.4)... Authenticated RCE in Bamboo Data Center with zero user interaction - enterprise CI/CD infrastructure just became the pe... https://zerodaysignal.com/vulnerability/CVE-2026-21571 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    Atlassian discloses CVE-2026-21571, an authenticated remote code execution vulnerability in Bamboo Data Center, scoring 9.4 on CVSS. No PoC, exploit, active exploitation evidence, or patch details are provided in the announcement.

    0000062
    218 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appatlassianbamboo---

Explore more