Critical Bamboo Data Centre and Server Flaw Enables Command Injection Attacks
ID: 2695ca9a-1b12-5704-a04f-65e3d949e0b3
STIX ID: report--2695ca9a-1b12-5704-a04f-65e3d949e0b3
Feed Name: GBHackers
Threat Score
Atlassian disclosed a critical OS command injection vulnerability (CVE-2026-21571, CVSS 9.4) affecting multiple Bamboo Data Center and Server releases that could allow authenticated attackers to execute arbitrary OS commands, risking confidentiality, integrity, and availability of CI/CD pipelines and software supply chains; Atlassian provides fixed versions (e.g., 12.1.6, 10.2.18, 9.6.25) and recommends immediate patching and auditing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
