CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Atlassian Jira Service Management Data Center

product · product:atlassian-jira-service-management-data-center single-source

Coverage
1
first 2026-10-06 → last 2026-10-06
Latest activity
2026-10-06
Atlassian: unauthenticated file access in every Data Center version of eight products; patch or take them…
Peak priority
high
1 high
Targets
technology
sectors: technology
Sources cited
4
3 hosts

Action items (2)

Do-now tasks recorded on the entries about Atlassian Jira Service Management Data Center, newest first. Check the date before acting on an older one.

  • Upgrade every Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd Data Center installation to a fixed version of its line (Bitbucket 9.4.26, 10.2.8 or 10.5.1; Confluence 9.2.26 or 10.2.19; Jira Service Management 5.12.40, 10.3.26 or 11.3.12; Jira Software 9.12.40, 10.3.26 or 11.3.12; Bamboo 10.2.24 or 12.1.12; Crowd 6.3.7, 7.0.3, 7.1.7 or 7.2.4) and Crucible and Fisheye to 4.9.15, internet-reachable instances first; until each is upgraded, take it off the internet or put Atlassian's web application firewall or Tomcat rewrite rule in front of it.
    2026-10-06CVE-2026-21589
  • On every Data Center instance that was internet-reachable, URL-decode the access logs for the whole exposure period (up to two decoding passes) and search for '..' directly next to '/', '\\' or '::', as Atlassian describes; Atlassian cannot say whether any instance was affected.
    2026-10-06CVE-2026-21589

Defender insights

What each entry about Atlassian Jira Service Management Data Center tells a defender to do, newest first.

2026-10-06HIGHAtlassian: unauthenticated file access in every Data Center version of eight products; patch or take them offline

Exposure · detection

Story timeline

  1. 2026-10-06CVE-2026-21589, Atlassian Data Center: unauthenticated arbitrary file access in every version of eight self-managed products, patch or take them off the internet (CVSS 4.0 9.3)
    trending-vulnerabilitiesAtlassian: unauthenticated file access in every Data Center version of eight products; patch or take them offline

Hunting pivots

Releases covered
Atlassian Jira Service Management Data Center
ATT&CK techniques (2 across 2 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application
  • CollectionData from Local System

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-06/cve-2026-21589-atlassian-data-center-arbitrary-file-access · ATT&CK page ↗

Collection TA0009

T1005Data from Local System×1

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Evidence: 2026-10-06/cve-2026-21589-atlassian-data-center-arbitrary-file-access · ATT&CK page ↗

Entries about Atlassian Jira Service Management Data Center (1)

2026-10-06 · view entry permalink →

HIGHCVE-2026-21589NATOA2

CVE-2026-21589, Atlassian Data Center: unauthenticated arbitrary file access in every version of eight self-managed products, patch or take them off the internet (CVSS 4.0 9.3)

Atlassian's advisory of 2026-10-05 says every version of Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd Data Center, and of Crucible and Fisheye, is affected by CVE-2026-21589, an arbitrary file access flaw that lets an unauthenticated attacker access specific files within the web application root directory (Atlassian, 2026-10-05). The attacker needs the target file's exact name and path and cannot enumerate or list directory contents, and Atlassian adds that in some configurations sensitive files are present that increase the risk (Atlassian, 2026-10-05). Atlassian's public ticket for Confluence Data Center labels the weakness "Path Traversal (Arbitrary Read/Write)" (Atlassian, 2026-10-02), while the advisory's CVSS 4.0 vector (9.3, Critical: network, low complexity, no privileges, no user interaction) rates the confidentiality impact high and the integrity and availability impact none on the vulnerable system, with high confidentiality, integrity and availability impact on subsequent systems (Atlassian, 2026-10-05). Atlassian Cloud is already patched and Atlassian says its investigation found no evidence of exploitation (Atlassian, 2026-10-05); The Register reports that Atlassian emailed customers on Monday pointing to the advisory (The Register, 2026-10-06).

The fixed versions are Bitbucket Data Center 9.4.26, 10.2.8 and 10.5.1; Confluence Data Center 9.2.26 and 10.2.19; Jira Service Management Data Center 5.12.40, 10.3.26 and 11.3.12; Jira Software Data Center 9.12.40, 10.3.26 and 11.3.12; Bamboo Data Center 10.2.24 and 12.1.12; Crowd Data Center 6.3.7, 7.0.3, 7.1.7 and 7.2.4; and Crucible and Fisheye 4.9.15 (Atlassian, 2026-10-05). Atlassian's Confluence ticket adds that versions past end of life may also be affected (Atlassian, 2026-10-02), and its Crowd ticket lists 7.1.6 as the fixed 7.1 build where the advisory lists 7.1.7 (Atlassian, 2026-10-02). Until a patch is applied, Atlassian says to remove the instance from the internet where possible, including instances that require user authentication, or to block at a web application firewall or proxy any URL that carries '..' directly next to a slash, backslash or '::' in plain or percent-encoded form; it also gives a Tomcat RewriteValve rule for Confluence, Jira Service Management, Jira Software, Bamboo and Crowd and a urlrewrite.xml rule for Bitbucket (Atlassian, 2026-10-05).

This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions.

Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents.

Affected Atlassian Cloud products have been patched, and our investigation has not found evidence of exploitation.

Remove your instance from the internet until you can patch or apply mitigations, if possible.

Atlassian 2026-10-05
vulnerability06 Oct 04:56Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • jira.atlassian.com2 (50%)
  • confluence.atlassian.com1 (25%)
  • theregister.com1 (25%)