Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589)
Atlassian warns unauthenticated attackers can read files on Data Center products via critical CVE-2026-21589.
Atlassian disclosed CVE-2026-21589, a critical arbitrary file access flaw scored 9.3 under CVSS 4.0, affecting all versions of its Data Center products including Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye. An unauthenticated attacker who knows an exact file name and path can read files under the web application root, but cannot enumerate directories. Cloud products are patched and Atlassian reported no evidence of exploitation; it urges Data Center customers to upgrade to fixed releases or take instances off the internet.
- CVE-2026-21589 scores 9.3 and allows unauthenticated file reads.
- Attackers must know the exact path and cannot list directories.
- Atlassian found no exploitation; affected cloud products are already patched.
- Data Center admins should upgrade or remove instances from the internet.
Vulnerabilities mentionedAll →
- CVE-2026-215899.32%This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access…published PoC ×7
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21589 | This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access… |
Full article348 words · extracted from helpnetsecurity.com · click to collapse
Attackers who know where to look can read files from Atlassian Data Center installations without logging in, the company has warned.

About CVE-2026-21589
CVE-2026-21589, a critical arbitrary file access vulnerability with a 9.3 CVSS score, affects all versions of Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.
Atlassian calculated the CVSS 4.0 score through its internal assessment and published the advisory on 5 October 2026.
“This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions,” reads the advisory.
“In some configurations, there may be sensitive files present that increase your risk,” Atlassian noted.
On the positive side, an attacker has to know the exact name and path of the target file to exploit it, and cannot use it to list or enumerate directory contents.
According to the company, the affected cloud products have been patched, its investigation found no evidence of exploitation, and customers using them do not need to take any action.
Fixes and temporary mitigations
Atlassian urges administrators to immediately upgrade each affected installation to a fixed version or to the latest release. The fixed versions are:
- Bitbucket Data Center 9.4.26, 10.2.8 and 10.5.1
- Confluence Data Center 9.2.26 and 10.2.19
- Jira Software Data Center and Jira Service Management Data Center 10.3.26 and 11.3.12 (also 9.12.40 for Jira Software and 5.12.40 for Jira Service Management)
- Bamboo Data Center 10.2.24 and 12.1.12
- Crowd Data Center 6.3.7, 7.0.3, 7.1.7 and 7.2.4
- Crucible and Fisheye 4.9.15
Atlassian recommends taking affected instances off the internet, if possible.
“Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action.”
The company has also published three temporary mitigations.
Atlassian cannot confirm whether customers’ instances have been affected and advises them to have their security teams check all affected instances for evidence of compromise.
The advisory does not mention whether the flaw has been exploited against Data Center instances, or who discovered it.