CVE-2026-21575
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows.
* Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13
Detalles técnicos trazas, registros y código del informe original
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: See the release notes (https://www.sourcetreeapp.com/download-archives). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center (https://www.sourcetreeapp.com/download-archives). This vulnerability was reported via our Bug Bounty program.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.59%
- Percentil entre todas las CVEs puntuadas: 46
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution95 % - Impacto principal
T1059Command and Scripting Interpreterexecution90 % - Impacto secundario
T1068Exploitation for Privilege Escalationprivilege escalation75 %
RCE en cliente (Sourcetree) requiere interacción del usuario (UI:R) para ejecutar código arbitrario con CVSS 7.1. Resulta en ejecución de comandos (T1059) y potencial escalada de privilegios del proceso.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-94
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-21575",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-21575",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-07-23T00:00:00+00:00"
}
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "security@atlassian.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "security@atlassian.com",
"affectedData": [
{
"vendor": "Atlassian",
"product": "Sourcetree for Mac",
"versions": [
{
"status": "affected",
"version": "All versions from 3.4.11 to 3.4.12 inclusive"
},
{
"status": "unaffected",
"version": "All versions from 3.4.13"
}
]
}
]
}
],
"published": "2026-07-21T18:16:57.170",
"references": [
{
"url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999345",
"tags": [
"Vendor Advisory"
],
"source": "security@atlassian.com"
},
{
"url": "https://jira.atlassian.com/browse/SRCTREE-8275",
"tags": [
"Issue Tracking"
],
"source": "security@atlassian.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. \n\t\n\tThis RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. \n\t\n\tAtlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\t\t\n\t\t* Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13\n\t\t\n\t\t\n\t\n\tSee the release notes (https://www.sourcetreeapp.com/download-archives). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center (https://www.sourcetreeapp.com/download-archives). \n\t\n\tThis vulnerability was reported via our Bug Bounty program."
}
],
"lastModified": "2026-08-10T20:51:43.367",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:atlassian:sourcetree:*:*:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "6C25407E-198E-43D6-A752-463CE72E4421",
"versionEndExcluding": "3.4.13",
"versionStartIncluding": "3.4.11"
},
{
"criteria": "cpe:2.3:a:atlassian:sourcetree:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "1A3303E7-2F00-4469-91F0-F39DBE138B1F",
"versionEndExcluding": "3.4.13",
"versionStartIncluding": "3.4.11"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@atlassian.com"
}