Atlassian CVE-2026-21589 file access flaw hits 8 Data Center products
At a glance
| Severity | CRITICAL |
|---|---|
| CVSS | CVE-2026-21589: 9.3 |
| In CISA KEV (exploited) | No |
| Vendor | Atlassian |
| CVE IDs | CVE-2026-21589 |
Atlassian has disclosed CVE-2026-21589, a critical arbitrary file access flaw affecting eight self-hosted Data Center products, including Confluence, Jira and Bitbucket. An unauthenticated remote attacker can read specific files in the web application root directory, and the flaw is rated 9.3 on the CVSS 4.0 scale. No exploitation in the wild has been reported in the sources we reviewed, and the flaw is not listed in CISA’s KEV catalog.
Atlassian published the advisory on October 5, 2026, and fixed versions exist for every affected product. This Atlassian vulnerability needs no login, so internet-facing instances are the first priority.
What happened
According to the NVD record and The Hacker News, the flaw lets an attacker with no credentials fetch files from the directory where the web application itself is installed. There is an important limit: the attacker must already know the exact file name and path, and the flaw cannot be used to list or browse directory contents.
Atlassian warns that in some configurations the web application root may hold sensitive files, which is why the rating is so high. Atlassian’s cloud products were already patched, and cloud customers need to do nothing.
Am I affected by CVE-2026-21589?
All versions of the eight products below that predate the fixed versions are affected, which may include end-of-life releases. Atlassian recommends moving to a fixed long-term support (LTS) release or later.
| Product | Introduced in | Fixed versions |
|---|---|---|
| Bitbucket Data Center | 4.6.0 | 9.4.26, 10.2.8, 10.5.1 |
| Confluence Data Center | 5.10.0 | 9.2.26, 10.2.19 |
| Jira Software Data Center | 7.1.0 | 9.12.40, 10.3.26, 11.3.12 |
| Jira Service Management Data Center | 3.1.0 | 5.12.40, 10.3.26, 11.3.12 |
| Bamboo Data Center | 7.0.1 | 10.2.24, 12.1.12 |
| Crowd Data Center | 2.11.0 | 6.3.7, 7.0.3, 7.1.7 (see note), 7.2.4 |
| Crucible | not disclosed | 4.9.15 |
| Fisheye | not disclosed | 4.9.15 |
Conflicting version data. The sources disagree on a few details, so verify against Atlassian’s own ticket for your product:
- For Crowd 7.1, the NVD text lists 7.1.1, while The Hacker News reports the ticket’s fix version field as 7.1.7 and notes a table in the same ticket that listed 7.1.6 as affected.
- The Hacker News reports that Atlassian’s CVE record gave inconsistent numbers for Bamboo (10.2.4 in one field, 10.2.24 in the description).
- The CVE record reportedly also lists Server editions of several products as affected with no fixed versions, while the advisory does not mention them. Whether Server licences can run the fixed releases was not stated.
When in doubt, use the higher fixed version.
Technical details
- CVE: CVE-2026-21589, published to NVD on 2026-10-05.
- CVSS 4.0: 9.3 (critical), vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N. Network reachable, low complexity, no privileges, no user interaction. Confidentiality impact is high; integrity and availability impact on the vulnerable system are none.
- Weakness: NVD lists no CWE. Per The Hacker News, Atlassian labels the issue a path traversal in the CVE record, meaning a crafted request escapes the intended directory.
- Exploitation status: not in CISA KEV; EPSS score not available at time of writing; no public exploit details in our sources.
Why this matters
Analysis, not new facts. The need to know an exact file path lowers the chance of mass data theft, but it does not make this safe to defer. Attackers can guess common, well-documented paths for configuration or deployment files, and Atlassian products are widely deployed and heavily scanned once a flaw is public. Treat any internet-facing instance as exposed and move it to the front of the queue. If the flaw later appears in KEV, patch within hours rather than days.
What to do: how to fix CVE-2026-21589
- Inventory every Data Center instance of the eight products, including Crucible and Fisheye, and note the running version.
- Upgrade to a fixed version from the table above, preferring a fixed LTS release.
- If you cannot upgrade immediately, Atlassian advises taking the instance offline where possible. Restrict any internet-reachable instance, even one that requires login, from outside network access until it is upgraded or a temporary blocking rule is in place.
- Review what sits in each web application root directory and remove or relocate anything sensitive that does not need to be there.
- Do not assume cloud action is needed: Atlassian reports its cloud products are already patched.
Detection and hunting ideas
No indicators of compromise have been published. Based on the nature of the flaw, consider the following, as suggestions rather than confirmed signatures:
- Search web server and reverse proxy logs for unauthenticated requests that return a successful response for unusual or non-application file names in the application root.
- Look for path traversal patterns such as encoded
../sequences in request URLs against Atlassian hosts. - Flag repeated requests from one source probing for common configuration file names.
- If sensitive files were present in the web root on an exposed instance, rotate any secrets they contained.
Sources
- NVD: CVE-2026-21589
- Atlassian ticket: Confluence Data Center (CONFSERVER-104488)
- Atlassian ticket: Jira Software Data Center (JRASERVER-79546)
- Atlassian ticket: Bitbucket Data Center (BSERV-20604)
- The Hacker News: Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
