Atlassian Bamboo Data Center Vulnerability Allows Code Execution
Summary
CERT-Bund has issued a security advisory regarding a vulnerability in Atlassian Bamboo Data Center versions prior to 9.6.24, 10.2.16, and 12.1.3. The vulnerability allows remote, authenticated attackers to execute arbitrary code, posing a high risk.
What changed
This security advisory from CERT-Bund details a critical vulnerability (CVSS Base Score 7.2) in Atlassian Bamboo Data Center. Versions prior to 9.6.24, 10.2.16, and 12.1.3 are affected. The flaw enables remote, authenticated attackers to execute arbitrary code on the affected systems, which are used for continuous integration and deployment.
Organizations using the affected versions of Atlassian Bamboo Data Center must apply the available mitigations or update to a patched version immediately to prevent potential code execution attacks. The advisory indicates that mitigation is available, and users should consult the provided links for specific patching instructions and further details on the CVE. Failure to address this vulnerability could lead to system compromise and data breaches.
What to do next
- Update Atlassian Bamboo Data Center to a patched version (>= 9.6.24, >= 10.2.16, or >= 12.1.3)
- Apply available mitigations if immediate update is not possible
Source document (simplified)
[WID-SEC-2026-0810] Atlassian Bamboo Data Center: Schwachstelle ermöglicht Codeausführung CVSS Base Score 7.2 (hoch) CVSS Temporal Score 6.3 (mittel) Remoteangriff ja Datum 19.03.2026 Stand 20.03.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- Linux
- Sonstiges
- UNIX
- Windows
Produktbeschreibung
Bamboo ist ein Werkzeug zur kontinuierlichen Integration und Bereitstellung, das automatisierte Builds, Tests und Freigaben in einem einzigen Arbeitsablauf verbindet.
Produkte
19.03.2026
- Atlassian Bamboo Data Center <9.6.24
Atlassian Bamboo Data Center <10.2.16
Atlassian Bamboo Data Center <12.1.3
Angriff
Angriff
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Atlassian Bamboo Data Center ausnutzen, um beliebigen Programmcode auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Privacy & Cybersecurity alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.