Critical CVSS 9.9 Atlassian Vulnerabilities Affect Bamboo, Bitbucket, Confluence, Jira
Summary
CERT-Bund issued a critical security advisory (WID-SEC-2026-1229) regarding multiple vulnerabilities in Atlassian Bamboo, Bitbucket, Confluence, and Jira with a CVSS Base Score of 9.9 (critical) and Temporal Score of 8.6 (high). Affected versions include Bamboo before 12.1.6 and 10.2.18, Bitbucket before 10.2.2 and 9.4.19, Confluence before 10.2.10 and 9.2.19, and Jira before 11.3.4 and 10.3.19. A remote attacker can exploit these flaws to execute arbitrary code, bypass security controls, manipulate or disclose data, or conduct Cross-Site-Scripting attacks. Organizations running these products should apply patches immediately and review available mitigations.
“Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.”
IT security teams managing Atlassian Bamboo, Bitbucket, Confluence, or Jira deployments should immediately verify installed versions against the affected version thresholds listed in the advisory and prioritize patching given the CVSS 9.9 severity and remote exploitation vector. The advisory confirms mitigations are available, so organizations should consult Atlassian's official security bulletins for the specific patch or workaround applicable to their version branch.
About this source
GovPing monitors CERT-Bund Security Advisories for new data privacy & cybersecurity regulatory changes. Every update since tracking began is archived, classified, and available as free RSS or email alerts — 368 changes logged to date.
What changed
CERT-Bund published a critical security advisory detailing multiple severe vulnerabilities (CVSS 9.9) affecting Atlassian Bamboo, Bitbucket, Confluence, Jira, and Jira Service Management across multiple version branches. The vulnerabilities enable remote attackers to execute arbitrary code, bypass security mechanisms, manipulate or exfiltrate data, and perform cross-site scripting attacks. The advisory lists specific affected version cutoffs for each affected product line. Organizations using these Atlassian products should immediately identify their current versions, compare against the vulnerable version thresholds, and apply available patches or mitigations as directed by Atlassian's security advisories. The critical CVSS score and remote exploitation vector make this a high-priority patching operation for any affected deployment.
Archived snapshot
Apr 22, 2026GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.
[WID-SEC-2026-1229] Atlassian Bamboo, Bitbucket, Confluence, Jira: Mehrere Schwachstellen CVSS Base Score 9.9 (kritisch) CVSS Temporal Score 8.6 (hoch) Remoteangriff ja Datum 21.04.2026 Stand 22.04.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- Sonstiges
- UNIX
- Windows
Produktbeschreibung
Bamboo ist ein Werkzeug zur kontinuierlichen Integration und Bereitstellung, das automatisierte Builds, Tests und Freigaben in einem einzigen Arbeitsablauf verbindet.
Bitbucket ist ein Git-Server zur Sourcecode-Versionskontrolle.
Confluence ist eine kommerzielle Wiki-Software.
Jira ist eine Webanwendung zur Softwareentwicklung.
Produkte
21.04.2026
- Atlassian Bamboo <12.1.6
Atlassian Bamboo <10.2.18
Atlassian Bitbucket <10.2.2
Atlassian Bitbucket <9.4.19
Atlassian Confluence <10.2.10
Atlassian Confluence <9.2.19
Atlassian Jira <11.3.4
Atlassian Jira <10.3.19
Atlassian Jira Service Management <11.3.4
Atlassian Jira Service Management <10.3.19
Angriff
Angriff
Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Related changes
Get daily alerts for CERT-Bund Security Advisories
Daily digest delivered to your inbox.
Free. Unsubscribe anytime.
Source
About this page
Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission
Source document text, dates, docket IDs, and authority are extracted directly from CERT-Bund.
The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.
Classification
Who this affects
Taxonomy
Browse Categories
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.
Subscribed!
Optional. Filters your digest to exactly the updates that matter to you.