---
schema: 1
kind: vulnerability
title: "CVE-2026-21589, Atlassian Data Center: unauthenticated arbitrary file access in every version of eight self-managed products, patch or take them off the internet (CVSS 4.0 9.3)"
headline: "Atlassian: unauthenticated file access in every Data Center version of eight products; patch or take them offline"
summary: >
  Atlassian's advisory of 2026-10-05 fixes CVE-2026-21589, an arbitrary file access flaw in the web application root of every
  version of Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd Data Center, plus Crucible and
  Fisheye (CVSS 4.0 9.3). The attacker must know a file's exact name and path and cannot list directories; Atlassian found
  no evidence of exploitation and tells customers to patch immediately or take internet-facing instances off the internet,
  with a web application firewall or Tomcat rewrite rule as the interim control.
discovered_at: "2026-10-06T04:56:00Z"
updated_at: null
event_date: "2026-10-05"
run_id: 2026-10-06T0405Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, path-traversal, pre-auth, info-disclosure, patch-available]
regions: [global]
sectors: [technology]
entities: ["product:atlassian-bitbucket-data-center", "product:atlassian-confluence-data-center", "product:atlassian-jira-service-management-data-center", "product:atlassian-jira-software-data-center", "product:atlassian-bamboo-data-center", "product:atlassian-crowd-data-center", "product:atlassian-crucible", "product:atlassian-fisheye"]
techniques: [T1190, T1005]
affected_products: ["Atlassian Bitbucket Data Center", "Atlassian Confluence Data Center", "Atlassian Jira Service Management Data Center", "Atlassian Jira Software Data Center", "Atlassian Bamboo Data Center", "Atlassian Crowd Data Center", "Atlassian Crucible", "Atlassian Fisheye"]
cves:
  - id: CVE-2026-21589
    cvss: "9.3"
    epss: null
    type: path-traversal
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "All versions of Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd Data Center, Crucible and Fisheye below the fixed versions; end-of-life versions may also be affected"
    fixed: "Bitbucket Data Center 9.4.26, 10.2.8, 10.5.1; Confluence Data Center 9.2.26, 10.2.19; Jira Service Management Data Center 5.12.40, 10.3.26, 11.3.12; Jira Software Data Center 9.12.40, 10.3.26, 11.3.12; Bamboo Data Center 10.2.24, 12.1.12; Crowd Data Center 6.3.7, 7.0.3, 7.1.7, 7.2.4; Crucible 4.9.15; Fisheye 4.9.15"
sources:
  - url: "https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html"
    publisher: "Atlassian"
    date: "2026-10-05"
    role: primary
  - url: "https://jira.atlassian.com/browse/CONFSERVER-104488"
    publisher: "Atlassian"
    date: "2026-10-02"
    role: corroborating
  - url: "https://jira.atlassian.com/browse/CWD-6610"
    publisher: "Atlassian"
    date: "2026-10-02"
    role: corroborating
  - url: "https://www.theregister.com/security/2026/10/06/atlassian-warns-of-critical-file-access-flaw-in-its-datacenter-products/5301284"
    publisher: "The Register"
    date: "2026-10-06"
    role: corroborating
closed_sources: []
evidence:
  - quote: "This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions."
    publisher: "Atlassian"
    source_url: "https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html"
  - quote: "Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents."
    publisher: "Atlassian"
    source_url: "https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html"
  - quote: "Affected Atlassian Cloud products have been patched, and our investigation has not found evidence of exploitation."
    publisher: "Atlassian"
    source_url: "https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html"
  - quote: "Remove your instance from the internet until you can patch or apply mitigations, if possible."
    publisher: "Atlassian"
    source_url: "https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html"
verification: single-source
sourcing_note: >
  Atlassian is the vendor and the CNA for its own products, and its advisory and tickets are the source for the flaw and its
  fixed versions; The Register restates the advisory and the customer email, and none of the cited sources reports
  exploitation or independent technical analysis. Atlassian's Crowd ticket lists 7.1.6 as the fixed 7.1 build where the advisory lists 7.1.7.
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Upgrade every Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd Data Center installation to a fixed version of its line (Bitbucket 9.4.26, 10.2.8 or 10.5.1; Confluence 9.2.26 or 10.2.19; Jira Service Management 5.12.40, 10.3.26 or 11.3.12; Jira Software 9.12.40, 10.3.26 or 11.3.12; Bamboo 10.2.24 or 12.1.12; Crowd 6.3.7, 7.0.3, 7.1.7 or 7.2.4) and Crucible and Fisheye to 4.9.15, internet-reachable instances first; until each is upgraded, take it off the internet or put Atlassian's web application firewall or Tomcat rewrite rule in front of it."
  - "On every Data Center instance that was internet-reachable, URL-decode the access logs for the whole exposure period (up to two decoding passes) and search for '..' directly next to '/', '\\' or '::', as Atlassian describes; Atlassian cannot say whether any instance was affected."
updates: []
migrated_from: null
---

Atlassian's advisory of 2026-10-05 says every version of Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd Data Center, and of Crucible and Fisheye, is affected by CVE-2026-21589, an arbitrary file access flaw that lets an unauthenticated attacker access specific files within the web application root directory ([Atlassian, 2026-10-05](https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html)). The attacker needs the target file's exact name and path and cannot enumerate or list directory contents, and Atlassian adds that in some configurations sensitive files are present that increase the risk ([Atlassian, 2026-10-05](https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html)). Atlassian's public ticket for Confluence Data Center labels the weakness "Path Traversal (Arbitrary Read/Write)" ([Atlassian, 2026-10-02](https://jira.atlassian.com/browse/CONFSERVER-104488)), while the advisory's CVSS 4.0 vector (9.3, Critical: network, low complexity, no privileges, no user interaction) rates the confidentiality impact high and the integrity and availability impact none on the vulnerable system, with high confidentiality, integrity and availability impact on subsequent systems ([Atlassian, 2026-10-05](https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html)). Atlassian Cloud is already patched and Atlassian says its investigation found no evidence of exploitation ([Atlassian, 2026-10-05](https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html)); The Register reports that Atlassian emailed customers on Monday pointing to the advisory ([The Register, 2026-10-06](https://www.theregister.com/security/2026/10/06/atlassian-warns-of-critical-file-access-flaw-in-its-datacenter-products/5301284)).

The fixed versions are Bitbucket Data Center 9.4.26, 10.2.8 and 10.5.1; Confluence Data Center 9.2.26 and 10.2.19; Jira Service Management Data Center 5.12.40, 10.3.26 and 11.3.12; Jira Software Data Center 9.12.40, 10.3.26 and 11.3.12; Bamboo Data Center 10.2.24 and 12.1.12; Crowd Data Center 6.3.7, 7.0.3, 7.1.7 and 7.2.4; and Crucible and Fisheye 4.9.15 ([Atlassian, 2026-10-05](https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html)). Atlassian's Confluence ticket adds that versions past end of life may also be affected ([Atlassian, 2026-10-02](https://jira.atlassian.com/browse/CONFSERVER-104488)), and its Crowd ticket lists 7.1.6 as the fixed 7.1 build where the advisory lists 7.1.7 ([Atlassian, 2026-10-02](https://jira.atlassian.com/browse/CWD-6610)). Until a patch is applied, Atlassian says to remove the instance from the internet where possible, including instances that require user authentication, or to block at a web application firewall or proxy any URL that carries '..' directly next to a slash, backslash or '::' in plain or percent-encoded form; it also gives a Tomcat RewriteValve rule for Confluence, Jira Service Management, Jira Software, Bamboo and Crowd and a urlrewrite.xml rule for Bitbucket ([Atlassian, 2026-10-05](https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html)).

**Exposure:** every self-managed Data Center installation of the eight products on a version below the fixed ones, internet-facing instances first, because Atlassian asks that even instances requiring user authentication be taken off the internet until patched; Atlassian Cloud customers need do nothing ([Atlassian, 2026-10-05](https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html)).

**Detection:** web server and reverse-proxy access logs. Atlassian says to URL-decode each request line (up to two decoding passes) and look for '..' directly next to '/', '\' or '::', or to search the raw lines with its regular expression; it cannot confirm whether any instance was affected and asks customers to check every affected instance for evidence of compromise ([Atlassian, 2026-10-05](https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html)).

**Defender takeaway:** upgrade each affected installation to a fixed version of its line now, internet-reachable ones first, and until each is upgraded keep it off the internet or behind Atlassian's rule; then search the access logs for the exposure period for traversal sequences, because no exploitation is reported but Atlassian cannot confirm that any instance is unaffected.
