Skip to content
THREATWIRE

CVE

CriticalPoC Available

CVE-2026-21589

Atlassian Data Center unauthenticated arbitrary file access

Atlassian CVE-2026-21589: unauthenticated attackers can read specific files under the web application root on multiple Data Center products if they know the exact path. CVSS 4.0 9.3. Path enumeration is not included. Public detector/PoC exists. Not in CISA KEV. Atlassian has not confirmed Data Center exploitation in the advisory.

CVSS
9.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Class
Info disclosure
Status
PoC Available
KEV
Not in CISA KEV
0-day
No
Vendor
Atlassian
Products
Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, Fisheye
Affected
All versions prior to the fixed versions listed by Atlassian for each product (Bitbucket from >=4.6.0; Confluence >=5.10.0; Crowd >=2.11.0; Jira Software >=7.1.0; Jira Service Management >=3.1.0; Bamboo >=7.0.1; plus Crucible and Fisheye lines per the advisory). Cloud products were patched by Atlassian.
Fixed
Bitbucket 9.4.26, 10.2.8, 10.5.1; Confluence 9.2.26, 10.2.19; Jira Service Management 5.12.40, 10.3.26, 11.3.12; Jira Software 9.12.40, 10.3.26, 11.3.12; Bamboo 10.2.24, 12.1.12; Crowd 6.3.7, 7.0.3, 7.1.7, 7.2.4; Crucible 4.9.15; Fisheye 4.9.15 (or later as Atlassian recommends).
Published
5 Oct 2026
Updated
7 Oct 2026

The status above is the claim. Links do not upgrade it.

CVE-2026-21589 is an arbitrary file-access vulnerability affecting multiple Atlassian Data Center and related self-managed products, disclosed in an Atlassian security advisory dated 5 October 2026. An unauthenticated attacker can access specific files within the web application root directory on affected versions. Exploitation requires prior knowledge of the target file’s exact name and path; the advisory states the vulnerability does not allow attackers to enumerate or list directory contents. Atlassian rates the issue Critical at CVSS 4.0 9.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H. CISA ADP maps CWE-552.

Products named in the advisory include Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Fixed maintenance builds are published per product (for example Bitbucket 9.4.26 / 10.2.8 / 10.5.1 and Confluence 9.2.26 / 10.2.19). Atlassian says affected Cloud products have been patched and that its Cloud investigation found no evidence of exploitation. For self-managed instances, Atlassian states it cannot confirm whether customer instances have been affected and recommends local compromise assessment.

NVD published the record on 5 October 2026 (Awaiting Analysis). CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to poc. GitHub advisory GHSA-gr66-x5pq-8g2g tracks the issue as critical.

watchTowr Labs published a public Detection Artifact Generator repository for CVE-2026-21589. The README describes a Python script that probes Jira, Confluence, and Bitbucket hosts and claims to report whether an instance appears vulnerable to the unauthenticated file-read condition. ThreatWire did not run it. Availability is therefore PoC. This record does not reprint traversal strings, plugin routes, or payloads.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-21589