CVE-2026-21589
Received Received - Intake

Arbitrary File Access in Atlassian Data Center Products

Vulnerability report for CVE-2026-21589, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Atlassian

Description

h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents.Β In some configurations, there may be some sensitive files that make this highly severe.Β Β  h3. Context This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. h3. Details: * The vulnerability must be addressed for affected versions of: Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.1, 7.2.4 Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 Crucible, fix versions 4.9.15 Fisheye, fix version 4.9.15 * Exploitation requires prior knowledge of the target file's exact name and path. * The vulnerability does not include the capability to enumerate or list directory contents.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
Atlassian Bamboo Data Center All other versions
Atlassian Bamboo Server All versions
Atlassian Bitbucket Data Center All other versions
Atlassian Bitbucket Server All versions
Atlassian Confluence Data Center All other versions
Atlassian Confluence Server All versions
Atlassian Crowd Data Center All other versions
Atlassian Crowd Server All versions
Atlassian Crucible Data Center All other versions
Atlassian Crucible Server All other versions
Atlassian Fisheye Data Center All other versions
Atlassian Fisheye Server All other versions
Atlassian Jira Service Management Data Center All other versions
Atlassian Jira Service Management Server All other versions
Atlassian Jira Software Data Center All other versions
Atlassian Jira Software Server All other versions

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Arbitrary File Access vulnerability in several Atlassian Data Center products. It allows unauthenticated attackers to access specific files within the web application root directory if they know the exact file name and path. The vulnerability does not permit directory listing or file enumeration.

Detection Guidance

Detection requires checking if affected Atlassian products are running vulnerable versions. Verify installed versions against the fixed versions listed in the CVE details. No direct exploitation commands are provided as this requires prior knowledge of specific file paths.

Impact Analysis

An attacker could access sensitive files, potentially exposing confidential data. Impact severity depends on the configuration and the files accessible. Some configurations may have highly sensitive files, making this vulnerability highly severe.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA if sensitive files are accessed through exploitation. Unauthorized access to files containing personal data or protected health information may violate these regulations, depending on the specific files exposed and organizational policies.

Mitigation Strategies

Immediately update affected Atlassian products to the specified fixed versions. If immediate updates are not possible, restrict network access to these services and monitor for suspicious file access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21589. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart