Junglewise Threat Intelligence

CVE-2026-21570: Atlassian Bamboo Data Center RCE in Apache Struts

CVE-2026-21570 · Severity: high · CVSS 8.8 · Published 2026-03-17

Vendors: Atlassian.

Executive brief

Atlassian Bamboo Data Center, a continuous integration and deployment platform used to automate software builds and deployments, contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary code on the server. Exploitation requires valid credentials but no additional user interaction, potentially giving attackers full control of the deployment pipeline and access to sensitive build artifacts and deployment credentials.

Technical details

This remote code execution vulnerability in Bamboo Data Center was introduced across multiple major versions (9.6.0 through 12.1.0) and requires authentication to exploit. The vulnerability allows an authenticated attacker to execute malicious code on the remote system with high severity impact. While the exact root cause is not detailed in the advisory, the related CVE-2025-68493 indicates a missing XML validation vulnerability in an Apache Struts dependency, suggesting the RCE may stem from unsafe deserialization or expression language injection within the Struts framework. The attack vector is network-based with high privilege requirements (authenticated user). Patches are available: Bamboo Data Center 9.6.x users should upgrade to 9.6.24 or later, 10.2.x users to 10.2.16 or later, and 12.1.x users to 12.1.3 or later.

Affected products

  • Atlassian Bamboo Data Center 9.6.0 to 9.6.23, 10.0.0 to 10.0.3, 10.1.0 to 10.1.1, 10.2.0 to 10.2.15, 11.0.0 to 11.0.8, 11.1.0, 12.0.0 to 12.0.2, 12.1.0 to 12.1.2

Timeline

  • 2026-03-17: disclosed
  • 2026-03-17: patched: Bamboo Data Center 9.6.24, 10.2.16, 12.1.3 and later

References