AI description
CVE-2026-21589 is a path traversal and arbitrary file access vulnerability that affects multiple self-hosted Atlassian Data Center and Server products, including Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye. The flaw allows remote, unauthenticated attackers to access specific files within the web application's root directory. To successfully exploit the vulnerability, an attacker must know the exact name and path of the target file, as the flaw does not allow directory listing or file enumeration. The vulnerability impacts all versions of the affected products prior to their designated fixed releases. While Atlassian's cloud-based services are secure and require no action, organizations utilizing self-hosted deployments are advised to upgrade to the patched versions. For systems that cannot be immediately updated, recommended mitigations include taking internet-facing instances offline, deploying web application firewall (WAF) rules, or configuring URL rewriting rules to block directory traversal attempts containing double-dot (`../`) sequences.
- Description
- This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.
- Source
- security@atlassian.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-552
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
4
【緊急】Atlassian Data Center製品に重大な脆弱性「CVE-2026-21589」──認証なしでファイル閲覧の恐れ、CVSS 9.3| @newsmatomenai https://t.co/BmD1ksKqFK
@newsmatomenai
7 Oct 2026
16 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Atlassian CVE-2026-21589 (CVSS 9.3): no-login path traversal reads known web-root files in 8 Data Center products incl. Jira and Confluence. Self-hosted: upgrade now (THN). #cybersecurity #infosec #Atlassian #CVE #AppSec https://t.co/N8EzZ7rNxb
@Caldura7
6 Oct 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589) www.helpnetsecurity.com/2026/10/06/atlassian-data-center-cve-2026-21589/ https://t.co/fPFRcewdiQ
@TheCyberSecHub
6 Oct 2026
1079 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Critical Atlassian (CVE-2026-21589) & WordPress (CVE-2026-87902) flaws are out with active exploitation. Meanwhile, Qilin and Everest ransomware groups are pushing new extortion victims across retail and finance. #ThreatIntel #CVE https://t.co/bO9XaqB3r1
@Npj8448
6 Oct 2026
61 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589) - https://t.co/KlIsRR36EZ - #Atlassian #Vulnerability #CVE #Cybersecurity #CyberSecurityNews #SecurityNews
@helpnetsecurity
6 Oct 2026
608 Impressions
0 Retweets
2 Likes
1 Bookmark
1 Reply
0 Quotes
Atlassian patched critical CVE-2026-21589, which allows unauthenticated file access. Users should patch immediately or restrict internet access. https://t.co/lFyGfFzsDm #Atlassian #vulnerability #CVE #critical #CyberSecurity #CybersecurityNews #threatresq #ThreatResQ
@ThreatResq
6 Oct 2026
54 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes