CVE-2026-21589

Published Oct 5, 2026

Last updated 8 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-21589 is a path traversal and arbitrary file access vulnerability that affects multiple self-hosted Atlassian Data Center and Server products, including Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye. The flaw allows remote, unauthenticated attackers to access specific files within the web application's root directory. To successfully exploit the vulnerability, an attacker must know the exact name and path of the target file, as the flaw does not allow directory listing or file enumeration. The vulnerability impacts all versions of the affected products prior to their designated fixed releases. While Atlassian's cloud-based services are secure and require no action, organizations utilizing self-hosted deployments are advised to upgrade to the patched versions. For systems that cannot be immediately updated, recommended mitigations include taking internet-facing instances offline, deploying web application firewall (WAF) rules, or configuring URL rewriting rules to block directory traversal attempts containing double-dot (`../`) sequences.

Description
This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.
Source
security@atlassian.com
NVD status
Awaiting Analysis

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-552

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

4

  1. 【緊急】Atlassian Data Center製品に重大な脆弱性「CVE-2026-21589」──認証なしでファイル閲覧の恐れ、CVSS 9.3| @newsmatomenai https://t.co/BmD1ksKqFK

    @newsmatomenai

    7 Oct 2026

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Atlassian CVE-2026-21589 (CVSS 9.3): no-login path traversal reads known web-root files in 8 Data Center products incl. Jira and Confluence. Self-hosted: upgrade now (THN). #cybersecurity #infosec #Atlassian #CVE #AppSec https://t.co/N8EzZ7rNxb

    @Caldura7

    6 Oct 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589) www.​helpnetsecurity.​com/2026/10/06/atlassian-data-center-cve-2026-21589/ https://t.co/fPFRcewdiQ

    @TheCyberSecHub

    6 Oct 2026

    1079 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 Critical Atlassian (CVE-2026-21589) & WordPress (CVE-2026-87902) flaws are out with active exploitation. Meanwhile, Qilin and Everest ransomware groups are pushing new extortion victims across retail and finance. #ThreatIntel #CVE https://t.co/bO9XaqB3r1

    @Npj8448

    6 Oct 2026

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589) - https://t.co/KlIsRR36EZ - #Atlassian #Vulnerability #CVE #Cybersecurity #CyberSecurityNews #SecurityNews

    @helpnetsecurity

    6 Oct 2026

    608 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  6. Atlassian patched critical CVE-2026-21589, which allows unauthenticated file access. Users should patch immediately or restrict internet access. https://t.co/lFyGfFzsDm #Atlassian #vulnerability #CVE #critical #CyberSecurity #CybersecurityNews #threatresq #ThreatResQ

    @ThreatResq

    6 Oct 2026

    54 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes