Skip to content
THREATWIRE

News

Atlassian arbitrary file access is CVE-2026-21589

Atlassian’s 5 October 2026 advisory for CVE-2026-21589 covers unauthenticated reads of known paths under the web root across Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye Data Center lines. CVSS 4.0 9.3. Public detector exists. Not in CISA KEV. Atlassian has not confirmed Data Center exploitation in the advisory.

Critical

Published 7 Oct 2026

PoC link

On this page

What happened

On 5 October 2026 Atlassian published a Critical security advisory for CVE-2026-21589 affecting multiple self-managed Data Center and related products. The vulnerability allows an unauthenticated attacker to access specific files inside the web application root directory. Atlassian rates it CVSS 4.0 9.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H. Exploitation requires knowing the exact file name and path; directory listing or enumeration is not part of the published impact.

Who is affected

Self-managed Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, and Crowd Data Center installations, plus Crucible and Fisheye, are in scope until patched to Atlassian’s fixed builds. Internet-exposed instances are highest priority. Atlassian states Cloud products have already been patched and require no customer action. Sensitive files under the web root in some configurations raise severity beyond a generic read.

What is confirmed

Atlassian’s advisory confirms unauthenticated access to specific known paths, the Critical 9.3 score, and fixed versions including Bitbucket 9.4.26 / 10.2.8 / 10.5.1; Confluence 9.2.26 / 10.2.19; Jira Software and Jira Service Management 9.12.40 or 5.12.40 / 10.3.26 / 11.3.12; Bamboo 10.2.24 / 12.1.12; Crowd 6.3.7 / 7.0.3 / 7.1.7 / 7.2.4; and Crucible / Fisheye 4.9.15. Temporary WAF and Tomcat rewrite mitigations are documented for operators who cannot patch immediately. NVD received the CVE on 5 October 2026. CISA ADP assigns CWE-552. The CVE is not in CISA KEV. CISA SSVC sets exploitation to poc.

For Cloud, Atlassian writes that its investigation found no evidence of exploitation. For self-managed Data Center, Atlassian states it cannot confirm whether customer instances have been affected and directs local security teams to review access logs.

watchTowr Labs published a public Detection Artifact Generator for CVE-2026-21589. The README describes a Python script that probes Jira, Confluence, and Bitbucket and claims to identify vulnerable instances via the unauthenticated file-read condition. ThreatWire did not run it. Availability is therefore PoC.

What is not confirmed

ThreatWire does not treat this advisory as CISA KEV–confirmed or Atlassian-confirmed Data Center exploitation. Third-party reports of scanning or honeypot hits after public technical write-ups are outside the Atlassian/KEV confirmation bar used for ThreatWire’s threats category. Claims that every Atlassian Cloud site remains vulnerable contradict Atlassian’s Cloud-patched statement. Directory browsing without a known path is not claimed by Atlassian.

What to do

Patch each affected product to a fixed version from the advisory table as soon as possible. If patching is delayed, restrict internet exposure and apply Atlassian’s temporary WAF or Tomcat/Bitbucket rewrite mitigations. Review access logs for traversal patterns as Atlassian describes (including URL-decoded forms). After patching, rotate credentials if sensitive files under the web root may have been exposed.

Sources: Atlassian advisory for CVE-2026-21589, NVD and CVE.org, GHSA-gr66-x5pq-8g2g, CISA KEV (not listed), and the watchTowr public detector repository metadata.

Related CVEs

Sources

Share on X@threatwire_https://www.threatwire.tech/news/atlassian-arbitrary-file-access-is-cve-2026-21589

More articles