NEWS

Atlassian Patches Critical Arbitrary File Access Flaw Affecting 8 Products

CVE-2026-21589 (CVSS 9.3) lets unauthenticated attackers read specific files on Bitbucket, Confluence, Jira, and five other Atlassian Data Center products.

Dylan H.

News Desk

October 7, 2026
3 min read
Atlassian Patches Critical Arbitrary File Access Flaw Affecting 8 Products

Critical Flaw Spans the Atlassian Data Center Lineup

Atlassian has released patches for a critical arbitrary file access vulnerability, tracked as CVE-2026-21589 with a CVSS score of 9.3, affecting eight separate Data Center products. The flaw allows an unauthenticated attacker to access specific files located in the web application's root directory — though exploitation comes with an important constraint.


Technical Details

FieldValue
CVE IDCVE-2026-21589
SeverityCritical (CVSS 9.3)
TypeArbitrary file access
AuthenticationNone required
Key ConstraintAttacker must know the exact target file's name and path — directory listing/enumeration is not possible

Atlassian's advisory is explicit that this bug does not allow attackers to browse or enumerate directory contents; the attacker needs to already know (or guess) the precise path of a file they want to read. That narrows — but does not eliminate — the practical risk, since many Atlassian deployments use predictable file layouts and configuration file names that a motivated attacker could guess or learn from public documentation.


Affected Products and Fixed Versions

ProductFixed Version(s)
Bitbucket Data Center9.4.26, 10.2.8, 10.5.1
Bamboo Data Center10.2.24, 12.1.12
Confluence Data Center9.2.26, 10.2.19
Crowd Data Center6.3.7, 7.0.3, 7.1.7, 7.2.4
Crucible4.9.15
Fisheye4.9.15
Jira Service Management Data Center5.12.40, 10.3.26, 11.3.12
Jira Software Data Center5.12.40, 10.3.26, 11.3.12

Why This Matters

Atlassian's Data Center products sit at the center of software development and IT service workflows for large organizations — source control (Bitbucket), CI/CD (Bamboo), documentation and wikis (Confluence), identity (Crowd), and ticketing (Jira). An arbitrary file read on any of these can expose:

  • Application configuration files containing database credentials or API keys
  • Source code or build artifacts stored outside the version-controlled repository
  • License files, internal documentation, or user data cached on disk

While Atlassian has not observed active exploitation of CVE-2026-21589 to date, the advisory notes that similar file-access and path-traversal vulnerabilities in Atlassian products have previously been exploited by ransomware groups and APT actors, making this a high-priority patch rather than a routine one.


  1. Identify every Atlassian Data Center instance in your environment across all eight affected products
  2. Apply the listed fixed version for each product as soon as possible — Data Center deployments often sit behind change-control processes, so start the approval cycle immediately
  3. Review file-access logs on affected instances for unusual requests targeting configuration or credential files
  4. Rotate credentials stored in configuration files if you cannot rule out prior exploitation before patching