Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-21589: Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, Fisheye allow file read

CVE-2026-21589 · published 4 days ago
Summary

An unauthenticated user can request certain files inside the web‑application folder of the listed Atlassian products if they already know the exact file name and path. This could expose configuration or other sensitive information, depending on what files are present. Apply the latest security patches for each product as soon as possible to close the issue.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
atlassian bamboo data center All other versions
atlassian bamboo server All versions
atlassian bitbucket data center All other versions
atlassian bitbucket server All versions
atlassian confluence data center All other versions
atlassian confluence server All versions
atlassian crowd data center All other versions
atlassian crowd server All versions
atlassian crucible data center All other versions
atlassian crucible server All other versions
atlassian fisheye data center All other versions
atlassian fisheye server All other versions
atlassian jira service management data center All other versions
atlassian jira service management server All other versions
atlassian jira software data center All other versions
atlassian jira software server All other versions
Original advisory text
This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye...
This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
2% chance of attack within 30 days
Type
CWE-552Files or Directories Accessible to External Parties
Timeline
Published5 Oct 2026
Updated9 Oct 2026
First seen5 Oct 2026
Sources
CVE-2026-21589 · MITRE
Track software like this
Free during beta