CVE-2026-54512
This High severity Insecure Deserialization vulnerability was introduced in versions 6.0.0, 6.1.0, 6.2.0, 6.3.6, 7.0.0, 7.1.0, and 7.2.0 of Crowd Data Center. This Insecure Deserialization vulnerability, with a CVSS Score of 8.1 and a CVSS Vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H allows an unauthenticated attacker to induce unintended behavior in the remote system, which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Crowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2 See the release notes ([https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html]). You can download the latest version of Crowd Data Center from the download center ([https://www.atlassian.com/software/crowd/download-archive]). The National Vulnerability Database provides the following description for this vulnerability: jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
EPSS 0.87% · 56.2th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Crucible Server | |
| Atlassian | Crowd Data Center | |
| Atlassian | Crucible Data Center |
Timeline
- Jun 23, 2026 CVE Published
- Jun 24, 2026 EPSS Score
- Jun 24, 2026 Coalition ESS Score
- Jun 25, 2026 Security Advisory
- Jul 9, 2026 Distribution Patch
- Jul 9, 2026 Security Advisory
- Jul 16, 2026 Distribution Patch
- Jul 16, 2026 Security Advisory
- Jul 20, 2026 Distribution Patch
- Jul 20, 2026 Security Advisory
- Jul 22, 2026 Distribution Patch
- Jul 22, 2026 Distribution Patch