-
Type:
Public Security Vulnerability
-
Resolution: Fixed
-
Priority:
Highest
-
Affects Version/s: 4.9.0, 4.9.1, 4.9.2, 4.9.3, 4.9.4, 4.9.5, 4.9.6, 4.9.7, 4.9.8, 4.9.9, 4.9.10, 4.9.11, 4.9.12, 4.9.13
-
Component/s: None
-
9.3
-
Critical
-
CVE-2026-59650
-
Atlassian (Internal)
-
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber
-
Injection
-
Crucible Data Center, Crucible Server
This is a vulnerability in a non-Atlassian Crucible Server dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
This Critical severity Injection vulnerability was introduced in version 4.9.0 of Crucible Server.
This Injection vulnerability, with a CVSS Score of 9.3 and a CVSS Vector of CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber allows an unauthenticated attacker to modify the actions taken by a system call.
Atlassian recommends that Crucible Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
- Crucible Server 4.9: Upgrade to a release greater than or equal to 4.9.14
See the release notes (https://confluence.atlassian.com/crucible/crucible-releases-298977378.html). You can download the latest version of Crucible Data Center and Server from the download center (https://www.atlassian.com/software/crucible/download-archives).
The National Vulnerability Database provides the following description for this vulnerability: In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.