CVE-2026-21589
Atlassian Data Center unauthenticated arbitrary file access
Atlassian CVE-2026-21589: unauthenticated attackers can read specific files under the web application root on multiple Data Center products if they know the exact path. CVSS 4.0 9.3. Path enumeration is not included. Public detector/PoC exists. Not in CISA KEV. Atlassian has not confirmed Data Center exploitation in the advisory.
- CVSS
- 9.3
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
- Class
- Info disclosure
- Status
- PoC Available
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Atlassian
- Products
- Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, Fisheye
- Affected
- All versions prior to the fixed versions listed by Atlassian for each product (Bitbucket from >=4.6.0; Confluence >=5.10.0; Crowd >=2.11.0; Jira Software >=7.1.0; Jira Service Management >=3.1.0; Bamboo >=7.0.1; plus Crucible and Fisheye lines per the advisory). Cloud products were patched by Atlassian.
- Fixed
- Bitbucket 9.4.26, 10.2.8, 10.5.1; Confluence 9.2.26, 10.2.19; Jira Service Management 5.12.40, 10.3.26, 11.3.12; Jira Software 9.12.40, 10.3.26, 11.3.12; Bamboo 10.2.24, 12.1.12; Crowd 6.3.7, 7.0.3, 7.1.7, 7.2.4; Crucible 4.9.15; Fisheye 4.9.15 (or later as Atlassian recommends).
- CWE
- CWE-552
- Published
- 5 Oct 2026
- Updated
- 7 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2026-21589 is an arbitrary file-access vulnerability affecting multiple Atlassian Data Center and related self-managed products, disclosed in an Atlassian security advisory dated 5 October 2026. An unauthenticated attacker can access specific files within the web application root directory on affected versions. Exploitation requires prior knowledge of the target file’s exact name and path; the advisory states the vulnerability does not allow attackers to enumerate or list directory contents. Atlassian rates the issue Critical at CVSS 4.0 9.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H. CISA ADP maps CWE-552.
Products named in the advisory include Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Fixed maintenance builds are published per product (for example Bitbucket 9.4.26 / 10.2.8 / 10.5.1 and Confluence 9.2.26 / 10.2.19). Atlassian says affected Cloud products have been patched and that its Cloud investigation found no evidence of exploitation. For self-managed instances, Atlassian states it cannot confirm whether customer instances have been affected and recommends local compromise assessment.
NVD published the record on 5 October 2026 (Awaiting Analysis). CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to poc. GitHub advisory GHSA-gr66-x5pq-8g2g tracks the issue as critical.
watchTowr Labs published a public Detection Artifact Generator repository for CVE-2026-21589. The README describes a Python script that probes Jira, Confluence, and Bitbucket hosts and claims to report whether an instance appears vulnerable to the unauthenticated file-read condition. ThreatWire did not run it. Availability is therefore PoC. This record does not reprint traversal strings, plugin routes, or payloads.