VDB

CVE-2026-54512

CVE-2026-54512 PUBLISHED CVSS 8.100000381469727 HIGH

This High severity Insecure Deserialization vulnerability was introduced in versions 6.0.0, 6.1.0, 6.2.0, 6.3.6, 7.0.0, 7.1.0, and 7.2.0 of Crowd Data Center. This Insecure Deserialization vulnerability, with a CVSS Score of 8.1 and a CVSS Vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H allows an unauthenticated attacker to induce unintended behavior in the remote system, which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Crowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2 See the release notes ([https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html]). You can download the latest version of Crowd Data Center from the download center ([https://www.atlassian.com/software/crowd/download-archive]). The National Vulnerability Database provides the following description for this vulnerability: jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

EPSS 0.87% · 56.2th percentile

Risk Scores

CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.87%
56.2th percentile

Affected Products

VendorProductVersions
AtlassianCrucible Server
AtlassianCrowd Data Center
AtlassianCrucible Data Center

Timeline

  • Jun 23, 2026 CVE Published
  • Jun 24, 2026 EPSS Score
  • Jun 24, 2026 Coalition ESS Score
  • Jun 25, 2026 Security Advisory
  • Jul 9, 2026 Distribution Patch
  • Jul 9, 2026 Security Advisory
  • Jul 16, 2026 Distribution Patch
  • Jul 16, 2026 Security Advisory
  • Jul 20, 2026 Distribution Patch
  • Jul 20, 2026 Security Advisory
  • Jul 22, 2026 Distribution Patch
  • Jul 22, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›