What is CVE-2026-21589?
The Arbitrary File Access vulnerability lets an attacker who is not logged in request specific files stored inside the web application root directory of an affected Atlassian product. Eight self-hosted products are affected: Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye Data Center. Atlassian states the attacker must already know the exact file name and path, because the vulnerability does not let anyone browse or list the directory to find files on their own.
Atlassian warns that some installations keep sensitive files inside that same directory, which raises the impact of a successful request. The vendor says all versions of each product are affected prior to the fixed releases, and it has published a fixed version for every affected product.
| CVE | Description | CVSS | Exploited in the wild |
|---|---|---|---|
| CVE-2026-21589 | Arbitrary File Access in Atlassian Data Center and Server Products | 9.3 Critical (CVSS 4.0) | Not reported |
Is CVE-2026-21589 being exploited in the wild?
As of October 6, 2026, no exploitation in the wild has been reported.
How did CVE-2026-21589 come to light?
Atlassian attached a mitigation file to the public Jira ticket tracking this issue for Jira Data Center on October 2, 2026. The company published its security advisory for the vulnerability on October 5, 2026, covering eight self-hosted products with fixed versions and mitigations. The available research does not name an external party who reported the issue.
How is watchTowr helping Atlassian customers?
- Rapid Reaction identified exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act.
- Active Defense released targeted network-level mitigations to clients, enabling immediate risk reduction while permanent fixes are applied.
What are Atlassian Data Center and Server Products?
Atlassian Data Center and Server Products are self-hosted versions of Atlassian’s software, including Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye, that organizations install and run on their own infrastructure for source code management, documentation, project tracking, build automation, identity management, and code review.
Which Atlassian products and versions are affected?
| Product | Affected Versions | Fixed Version |
|---|---|---|
| Bitbucket Data Center | All versions are affected | 9.4.26, 10.2.8, 10.5.1 |
| Confluence Data Center | All versions are affected | 9.2.26, 10.2.19 |
| Jira Service Management Data Center | All versions are affected | 5.12.40, 10.3.26, 11.3.12 |
| Jira Software Data Center | All versions are affected | 9.12.40, 10.3.26, 11.3.12 |
| Bamboo Data Center | All versions are affected | 10.2.24, 12.1.12 |
| Crowd Data Center | All versions are affected | 6.3.7, 7.0.3, 7.1.7, 7.2.4 |
| Crucible | All versions are affected | 4.9.15 |
| Fisheye | All versions are affected | 4.9.15 |
- Attackers need to already know the exact file name and path to exploit the vulnerability.
- The vulnerability does not let attackers browse or list directory contents to discover file names.
- Instances that store sensitive files inside the web application root directory face higher risk.
- All versions of the eight affected products are vulnerable, regardless of configuration.
Internet facing instances of Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, or Fisheye Data Center deserve attention first, since Atlassian treats every instance as at risk until it is patched or network-isolated, even when login is required.
How do I fix CVE-2026-21589?
Organizations should upgrade each affected instance to its listed fixed version as soon as possible. Until that happens, Atlassian recommends taking instances off the public internet and applying a web application firewall rule or server-level configuration change as a temporary workaround, though the vendor stresses these measures do not replace patching.
- Inventory every Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye Data Center instance in the environment.
- Restrict public internet access to affected instances until they are patched or mitigated.
- Apply the vendor’s web application firewall rule or server-level mitigation if patching cannot happen immediately.
- Upgrade each instance to its listed fixed version as soon as possible.
- Search access logs for requests containing two dots next to a slash, backslash, or double colon.
- Confirm with security teams whether logs show signs of file access attempts before the patch was applied.
How do I check the affected Atlassian products for compromise?
Atlassian suggests decoding each access log request line up to twice and searching for two dots positioned directly next to a slash, backslash, or double colon, which can indicate an attempt to escape the intended directory. The vendor also allows running its published pattern directly over raw log lines. Atlassian states it cannot tell individual customers whether their instance was affected, so security teams need to review their own logs for this pattern.
What types of threat actors typically exploit this vulnerability?
Historically, ransomware gangs and APT groups exploit these vulnerabilities.
Have there been similar Atlassian product vulnerabilities before?
Yes. These earlier Atlassian product vulnerabilities, including ones affecting Jira and Confluence, were added to the CISA KEV catalog after exploitation in the wild:
| CVE | Description | Added to KEV |
|---|---|---|
| CVE-2021-26086 | Atlassian Jira Server and Data Center Path Traversal Vulnerability | November 12, 2024 |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server Template Injection Vulnerability | January 24, 2024 |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server Improper Authorization Vulnerability | November 7, 2023 |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server Broken Access Control Vulnerability | October 5, 2023 |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center Command Injection Vulnerability | September 30, 2022 |
| CVE-2022-26134 | Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability | June 2, 2022 |
| CVE-2019-11581 | Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability | March 7, 2022 |
| CVE-2019-3398 | Atlassian Confluence Server and Data Center Path Traversal Vulnerability | November 3, 2021 |
