Vulnerabilities in Atlassian

408 results
Vexday analysis

Com 13 CVEs confirmadas em exploração ativa pelo CISA KEV de um total de 399 catalogadas, a taxa de exploração do portfólio Atlassian é 7,2 vezes acima da média geral do catálogo, o que indica atenção elevada por parte de agentes maliciosos a vulnerabilidades nesse ecossistema. O tipo de falha mais recorrente é CWE-863 (Autorização Incorreta), sugerindo deficiências estruturais em controles de acesso que tendem a ter impacto amplo em ambientes colaborativos. A CVE mais crítica em exploração ativa, CVE-2021-26084, apresenta EPSS máximo de 1,0 — indicador de probabilidade praticamente certa de exploração em campo —, o que a coloca como prioridade absoluta de remediação para qualquer organização que ainda não tenha aplicado os patches correspondentes. Com 19 vulnerabilidades com PoC pública e 22 de severidade crítica no portfólio total, a superfície de risco permanece significativa e exige monitoramento contínuo.

CVE-2019-20400The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global patEPSS 0.4%CVE-2020-4019The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different exEPSS 0.4%CVE-2021-43940HIGHAffected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the lEPSS 0.3%CVE-2026-21587HIGHThis High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. This ImEPSS 0.3%CVE-2026-21586HIGHThis High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, EPSS 0.3%CVE-2026-21575HIGHThis High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for WindoEPSS 0.3%CVE-2019-15002MEDIUMAn exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a EPSS 0.3%CVE-2026-21569HIGHThis High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server. ThEPSS 0.3%CVE-2026-21584HIGHThis High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of BamEPSS 0.3%CVE-2026-21588HIGHThis High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2,EPSS 0.3%CVE-2020-36233The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7EPSS 0.3%CVE-2026-21579HIGHThis High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2EPSS 0.3%CVE-2018-13399The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges becausEPSS 0.3%CVE-2024-21684LOWThere is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 tEPSS 0.2%CVE-2026-21577HIGHThis High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0EPSS 0.2%CVE-2025-22176MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of senEPSS 0.2%CVE-2025-22173MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of senEPSS 0.2%CVE-2025-22170MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they inEPSS 0.2%CVE-2025-22178MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of senEPSS 0.2%CVE-2025-22168MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of senEPSS 0.2%