PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-21575 Atlassian CVE debrief

CVE-2026-21575 is a High severity RCE (Remote Code Execution) vulnerability introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. The vulnerability has a CVSS Score of 7.1 and allows an authenticated attacker to execute arbitrary code, impacting confidentiality, integrity, and availability. User interaction is required. This vulnerability affects users of Sourcetree for Mac and Sourcetree for Windows, particularly those using version 3.4.11. An immediate review of current deployments and an upgrade plan should be prioritized.

Vendor
Atlassian
Product
Sourcetree for Mac
CVSS
HIGH 8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-08-10
Advisory published
2026-07-21
Advisory updated
2026-08-10

Who should care

Users of Sourcetree for Mac and Sourcetree for Windows, especially those using version 3.4.11, should upgrade to a fixed version to prevent potential RCE attacks. This includes operators, platform administrators, vulnerability management teams, and security teams responsible for maintaining and securing their software development environments.

Technical summary

The vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. It was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. The vulnerability can be mitigated by upgrading to a fixed version, specifically for Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13.

Defensive priority

High priority should be given to upgrading Sourcetree for Mac and Sourcetree for Windows to a fixed version, as the vulnerability allows for RCE and requires user interaction.

Recommended defensive actions

  • Upgrade Sourcetree for Mac and Sourcetree for Windows to the latest version.
  • If immediate upgrade is not possible, upgrade to one of the specified supported fixed versions: Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13.
  • Review and apply the release notes and download the latest version from the official download center.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability was reported via the Bug Bounty program. Limited details are available about the specific attack vector or exploitability. Further review of system logs and network traffic may be necessary to detect potential exploitation attempts. Additional verification steps should include checking for any suspicious activity related to user interactions with the affected Sourcetree versions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-21575 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-21575

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-21575 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21575

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.