2026-10-06HIGHAtlassian: unauthenticated file access in every Data Center version of eight products; patch or take them offline
Atlassian Data Center (Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, Fisheye), unauthenticated arbitrary file access in the web application root, CVSS 4.0 9.3, no exploitation reported
cve · CVE-2026-21589 single-source
Coverage
1
first 2026-10-06 → last 2026-10-06
Latest activity
2026-10-06
Atlassian: unauthenticated file access in every Data Center version of eight products; patch or take them…
Peak priority
high
1 high
Targets
technology
sectors: technology
Sources cited
4
3 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-21589, newest first. Check the date before acting on an older one.
- Upgrade every Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd Data Center installation to a fixed version of its line (Bitbucket 9.4.26, 10.2.8 or 10.5.1; Confluence 9.2.26 or 10.2.19; Jira Service Management 5.12.40, 10.3.26 or 11.3.12; Jira Software 9.12.40, 10.3.26 or 11.3.12; Bamboo 10.2.24 or 12.1.12; Crowd 6.3.7, 7.0.3, 7.1.7 or 7.2.4) and Crucible and Fisheye to 4.9.15, internet-reachable instances first; until each is upgraded, take it off the internet or put Atlassian's web application firewall or Tomcat rewrite rule in front of it.2026-10-06CVE-2026-21589
- On every Data Center instance that was internet-reachable, URL-decode the access logs for the whole exposure period (up to two decoding passes) and search for '..' directly next to '/', '\\' or '::', as Atlassian describes; Atlassian cannot say whether any instance was affected.2026-10-06CVE-2026-21589
Defender insights
What each entry about CVE-2026-21589 tells a defender to do, newest first.
Exposure · detection
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- CollectionData from Local System
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-10-06/cve-2026-21589-atlassian-data-center-arbitrary-file-access · ATT&CK page ↗
Collection TA0009
T1005Data from Local System×1
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
Evidence: 2026-10-06/cve-2026-21589-atlassian-data-center-arbitrary-file-access · ATT&CK page ↗
Entries about Atlassian Data Center (Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, Fisheye), unauthenticated arbitrary file access in the web application root, CVSS 4.0 9.3, no exploitation reported (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Atlassian Bamboo Data Center×1
- Atlassian Bitbucket Data Center×1
- Atlassian Confluence Data Center×1
- Atlassian Crowd Data Center×1
- Atlassian Crucible×1
- Atlassian Fisheye×1
- Atlassian Jira Service Management Data Center×1
- Atlassian Jira Software Data Center×1
Where this entity is cited
Source distribution
- jira.atlassian.com2 (50%)
- confluence.atlassian.com1 (25%)
- theregister.com1 (25%)
External references
All cited sources (4)
- confluence.atlassian.comprimaryAtlassianhttps://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html
- jira.atlassian.comAtlassianhttps://jira.atlassian.com/browse/CONFSERVER-104488
- jira.atlassian.comAtlassianhttps://jira.atlassian.com/browse/CWD-6610
- theregister.comThe Registerhttps://www.theregister.com/security/2026/10/06/atlassian-warns-of-critical-file-access-flaw-in-its-datacenter-products/5301284