{
 "description": "Evidence-bound MITRE ATT&CK techniques observed in CTIPilot entries referencing Atlassian Data Center (Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, Fisheye), unauthenticated arbitrary file access in the web application root, CVSS 4.0 9.3, no exploitation reported. Score = number of published entries mapping the technique. Pinned dataset: ATT&CK v19.2.",
 "domain": "enterprise-attack",
 "gradient": {
  "colors": [
   "#ffe766",
   "#ff6666"
  ],
  "maxValue": 1,
  "minValue": 0
 },
 "hideDisabled": false,
 "layout": {
  "layout": "side",
  "showID": true,
  "showName": true
 },
 "legendItems": [],
 "metadata": [
  {
   "name": "source",
   "value": "CTIPilot"
  },
  {
   "name": "entity",
   "value": "CVE-2026-21589"
  },
  {
   "name": "attack_version",
   "value": "19.2"
  }
 ],
 "name": "Atlassian Data Center (Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, Fisheye), unauthenticated arbitrary file access in the web application root, CVSS 4.0 9.3, no exploitation reported, CTIPilot coverage",
 "sorting": 3,
 "techniques": [
  {
   "comment": "entries: 2026-10-06/cve-2026-21589-atlassian-data-center-arbitrary-file-access",
   "score": 1,
   "techniqueID": "T1005"
  },
  {
   "comment": "entries: 2026-10-06/cve-2026-21589-atlassian-data-center-arbitrary-file-access",
   "score": 1,
   "techniqueID": "T1190"
  }
 ],
 "versions": {
  "attack": "19",
  "layer": "4.5",
  "navigator": "5.1.0"
 }
}