Atlassian security advisory (AV26-1002)
Canada's Cyber Centre warns Atlassian server products are affected by arbitrary file access CVE-2026-21589.
The Canadian Centre for Cyber Security issued advisory AV26-1002 on October 5, 2026, for Atlassian arbitrary file access vulnerability CVE-2026-21589. Affected products include specified Data Center and Server versions of Bamboo, Bitbucket, Confluence, Crowd, Crucible, Fisheye, Jira Service Management, and Jira Software, with all Server versions listed for several products. The Cyber Centre told administrators to review Atlassian's advisories and apply updates as they become available. The bulletin does not report that the flaw is being exploited.
- CVE-2026-21589 allows arbitrary file access in multiple Atlassian products
- Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye are affected
- Several Server product lines are vulnerable in all versions
- Advisory AV26-1002 tells administrators to apply available updates
- The bulletin does not report active exploitation
Vulnerabilities mentionedAll →
- CVE-2026-215899.32%This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access…published PoC ×7
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21589 | This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access… |
Full article203 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-1002
Date: October 5, 2026
As of October 5, 2026, Atlassian is affected by a vulnerability in the following products:
- Bamboo Data Center
- Version 10.2.4 and prior
- Version 12.1.12 and prior
- Bamboo Server
- All versions
- Bitbucket Data Center
- Version 10.2.8 and prior
- Version 10.5.1 and prior
- Version 9.4.26 and prior
- Bitbucket Server
- All versions
- Confluence Data Center
- Version 10.2.19 and prior
- Version 9.2.26 and prior
- Confluence Server
- All versions
- Crowd Data Center
- Version 6.3.7 and prior
- Version 7.0.3 and prior
- Version 7.1.1 and prior
- Version 7.2.4 and prior
- Crowd Server
- All versions
- Crucible Data Center
- Version 4.9.15 and prior
- Crucible Server
- Version 4.9.15 and prior
- Fisheye Data Center
- Version 4.9.15 and prior
- Fisheye Server
- Version 4.9.15 and prior
- Jira Service Management Data Center
- Version 10.3.26 and prior
- Version 11.3.12 and prior
- Version 5.12.40 and prior
- Jira Service Management Server
- Version 5.12.40 and prior
- Jira Software Data Center
- Version 10.3.26 and prior
- Version 11.3.12 and prior
- Version 9.12.40 and prior
- Jira Software Server
- Version 9.12.40 and prior
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/atlassian-security-advisory-av26-1002