Cyber Resilience

CVE-2012-2926

Atlassian Crowd ≤ 2.0.9

High EPSS
Published
22 May 2012
Modified
29 April 2026
Patch / advisory
CVSS Score v3.1 9.1
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS Score 0.67 99.2th percentile
Risk Priority 89 floored blend · peak EPSS

Summary

CVE-2012-2926 is a critical-severity an unspecified weakness vulnerability in Atlassian Crowd. Its CVSS base score is 9.1 (Critical).

Operationally, ranked in the top 0.8% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2,…

more

2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.

CWE(s)

Related Threats

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1190 Exploit Public-Facing Application Initial Accessconfidence: HIGH
The CVE describes a flaw in multiple Atlassian products that allows remote attackers to read arbitrary files via XML parsers, directly enabling exploitation of a public-facing application.
T1005 Data from Local System Collectionconfidence: HIGH
The vulnerability permits remote attackers to read arbitrary files on the affected systems.
T1499 Endpoint Denial of Service Impactconfidence: MEDIUM
The description notes the vulnerability can cause denial of service through resource consumption.
inferred from description · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2024-21683Same product: Atlassian Confluence Server
CVE-2019-3396Same product: Atlassian Confluence Server
CVE-2026-21569Same product: Atlassian Crowd
CVE-2024-21687Same product: Atlassian Bamboo
CVE-2019-11580Same product: Atlassian Crowd
CVE-2023-22516Same product: Atlassian Bamboo
CVE-2019-3398Same product: Atlassian Confluence Server
CVE-2024-21689Same product: Atlassian Bamboo
CVE-2023-22504Same product: Atlassian Confluence Server
CVE-2023-22521Same product: Atlassian Crowd

Affected Assets

atlassian
bamboo
≤ 3.3.4 · 3.4 — 3.4.5
atlassian
confluence
≤ 3.5.16
atlassian
confluence server
4.0 — 4.0.7 · 4.1 — 4.1.10
atlassian
crowd
≤ 2.0.9 · 2.1 — 2.1.2 · 2.2.0 — 2.2.9
atlassian
crucible
≤ 2.5.8 · 2.6 — 2.6.8 · 2.7 — 2.7.12
atlassian
fisheye
≤ 2.5.8 · 2.6 — 2.6.8 · 2.7 — 2.7.12
atlassian
jira
≤ 5.0.1

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References