Proactive Threat Intelligence from the team that finds the vulnerabilities. We publish what is being exploited right now, who is doing it, and whether it reaches you. No vendor summaries written a week late.

Updated Oct 6, 2026

Frequently Asked Questions About the Atlassian Jira & Confluence Arbitrary File Read Vulnerability (CVE-2026-21589)

CVE-2026-21589 is an Arbitrary File Access vulnerability affecting eight Atlassian Data Center and Server products, letting unauthenticated attackers read specific files without logging in. This FAQ is updated as new details emerge.

Status

CVE

CVE-2026-21589

CVSS

9.3 (v4.0)

Exploitation

None reported

CISA KEV

Not listed

Vendor patch

Available

Questions

Updates

Key takeaways

What is CVE-2026-21589?

The Arbitrary File Access vulnerability lets an attacker who is not logged in request specific files stored inside the web application root directory of an affected Atlassian product. Eight self-hosted products are affected: Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye Data Center. Atlassian states the attacker must already know the exact file name and path, because the vulnerability does not let anyone browse or list the directory to find files on their own.

Atlassian warns that some installations keep sensitive files inside that same directory, which raises the impact of a successful request. The vendor says all versions of each product are affected prior to the fixed releases, and it has published a fixed version for every affected product.

CVEDescriptionCVSSExploited in the wild
CVE-2026-21589Arbitrary File Access in Atlassian Data Center and Server Products9.3 Critical (CVSS 4.0)Not reported

Is CVE-2026-21589 being exploited in the wild?

As of October 6, 2026, no exploitation in the wild has been reported.

How did CVE-2026-21589 come to light?

Atlassian attached a mitigation file to the public Jira ticket tracking this issue for Jira Data Center on October 2, 2026. The company published its security advisory for the vulnerability on October 5, 2026, covering eight self-hosted products with fixed versions and mitigations. The available research does not name an external party who reported the issue.

How is watchTowr helping Atlassian customers?

  • Rapid Reaction identified exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act.
  • Active Defense released targeted network-level mitigations to clients, enabling immediate risk reduction while permanent fixes are applied.

What are Atlassian Data Center and Server Products?

Atlassian Data Center and Server Products are self-hosted versions of Atlassian’s software, including Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye, that organizations install and run on their own infrastructure for source code management, documentation, project tracking, build automation, identity management, and code review.

Which Atlassian products and versions are affected?

ProductAffected VersionsFixed Version
Bitbucket Data CenterAll versions are affected9.4.26, 10.2.8, 10.5.1
Confluence Data CenterAll versions are affected9.2.26, 10.2.19
Jira Service Management Data CenterAll versions are affected5.12.40, 10.3.26, 11.3.12
Jira Software Data CenterAll versions are affected9.12.40, 10.3.26, 11.3.12
Bamboo Data CenterAll versions are affected10.2.24, 12.1.12
Crowd Data CenterAll versions are affected6.3.7, 7.0.3, 7.1.7, 7.2.4
CrucibleAll versions are affected4.9.15
FisheyeAll versions are affected4.9.15
  • Attackers need to already know the exact file name and path to exploit the vulnerability.
  • The vulnerability does not let attackers browse or list directory contents to discover file names.
  • Instances that store sensitive files inside the web application root directory face higher risk.
  • All versions of the eight affected products are vulnerable, regardless of configuration.

Internet facing instances of Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, or Fisheye Data Center deserve attention first, since Atlassian treats every instance as at risk until it is patched or network-isolated, even when login is required.

How do I fix CVE-2026-21589?

Organizations should upgrade each affected instance to its listed fixed version as soon as possible. Until that happens, Atlassian recommends taking instances off the public internet and applying a web application firewall rule or server-level configuration change as a temporary workaround, though the vendor stresses these measures do not replace patching.

  1. Inventory every Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye Data Center instance in the environment.
  2. Restrict public internet access to affected instances until they are patched or mitigated.
  3. Apply the vendor’s web application firewall rule or server-level mitigation if patching cannot happen immediately.
  4. Upgrade each instance to its listed fixed version as soon as possible.
  5. Search access logs for requests containing two dots next to a slash, backslash, or double colon.
  6. Confirm with security teams whether logs show signs of file access attempts before the patch was applied.

How do I check the affected Atlassian products for compromise?

Atlassian suggests decoding each access log request line up to twice and searching for two dots positioned directly next to a slash, backslash, or double colon, which can indicate an attempt to escape the intended directory. The vendor also allows running its published pattern directly over raw log lines. Atlassian states it cannot tell individual customers whether their instance was affected, so security teams need to review their own logs for this pattern.

What types of threat actors typically exploit this vulnerability?

Historically, ransomware gangs and APT groups exploit these vulnerabilities.

Have there been similar Atlassian product vulnerabilities before?

Yes. These earlier Atlassian product vulnerabilities, including ones affecting Jira and Confluence, were added to the CISA KEV catalog after exploitation in the wild:

CVEDescriptionAdded to KEV
CVE-2021-26086Atlassian Jira Server and Data Center Path Traversal VulnerabilityNovember 12, 2024
CVE-2023-22527Atlassian Confluence Data Center and Server Template Injection VulnerabilityJanuary 24, 2024
CVE-2023-22518Atlassian Confluence Data Center and Server Improper Authorization VulnerabilityNovember 7, 2023
CVE-2023-22515Atlassian Confluence Data Center and Server Broken Access Control VulnerabilityOctober 5, 2023
CVE-2022-36804Atlassian Bitbucket Server and Data Center Command Injection VulnerabilitySeptember 30, 2022
CVE-2022-26134Atlassian Confluence Server and Data Center Remote Code Execution VulnerabilityJune 2, 2022
CVE-2019-11581Atlassian Jira Server and Data Center Server-Side Template Injection VulnerabilityMarch 7, 2022
CVE-2019-3398Atlassian Confluence Server and Data Center Path Traversal VulnerabilityNovember 3, 2021

If you are a watchTowr client

Rapid Reaction identified exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act. Active Defense released targeted network-level mitigations to clients, enabling immediate risk reduction while permanent fixes are applied. Contact your watchTowr team with any questions.

Want to know if this reaches you, before the next one?

watchTowr validates exposure and mitigates at the edge in under an hour.

Attackers Don't Give Up. Neither Should Your Security Testing.

Zero install. No infrastructure changes. Uplift your security posture within hours of onboarding the watchTowr Platform.

Find Out What an Attacker Can Reach Before They Do.

Point us at a domain. We reconstruct your real external estate and come back with validated exposure, not a theoretical CVE list.

Disclosure to Exploitation Is Four Hours. Patching Is Not.

The watchTowr Platform validates your exposure to an emerging threat and mitigates it at the edge while the vendor patch is still in testing.

We Find the Vulnerabilities. You Hear It From Us First.

watchTowr Labs publishes what is being exploited right now and whether it touches your estate, not vendor summaries written a week late.

Your Exposure Changes Weekly. Annual Testing Cannot Describe It.

Continuous, fully external validation of what an attacker can actually exploit against your estate, at a 0.01% false-positive rate.

See the Estate You Own, Including What No Asset List Holds.

Subsidiaries, forgotten infrastructure, shadow IT. We rebuild your external surface from a single domain, then validate what is exposed.