Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-21589: Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, Fisheye allow file read
CVE-2026-21589 · published 4 days ago
Summary
An unauthenticated user can request certain files inside the web‑application folder of the listed Atlassian products if they already know the exact file name and path. This could expose configuration or other sensitive information, depending on what files are present. Apply the latest security patches for each product as soon as possible to close the issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| atlassian | bamboo data center | All other versions |
| atlassian | bamboo server | All versions |
| atlassian | bitbucket data center | All other versions |
| atlassian | bitbucket server | All versions |
| atlassian | confluence data center | All other versions |
| atlassian | confluence server | All versions |
| atlassian | crowd data center | All other versions |
| atlassian | crowd server | All versions |
| atlassian | crucible data center | All other versions |
| atlassian | crucible server | All other versions |
| atlassian | fisheye data center | All other versions |
| atlassian | fisheye server | All other versions |
| atlassian | jira service management data center | All other versions |
| atlassian | jira service management server | All other versions |
| atlassian | jira software data center | All other versions |
| atlassian | jira software server | All other versions |
Original advisory text
This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye...
This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.
References
- https://github.com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589
- https://jira.atlassian.com/browse/BAM-26567
- https://jira.atlassian.com/browse/BSERV-20604
- https://jira.atlassian.com/browse/CONFSERVER-104488
- https://jira.atlassian.com/browse/CRUC-8741
- https://jira.atlassian.com/browse/CWD-6610
- https://jira.atlassian.com/browse/FE-7583
- https://jira.atlassian.com/browse/JRASERVER-79546
- https://jira.atlassian.com/browse/JSDSERVER-16809
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-552Files or Directories Accessible to External Parties
Timeline
Published5 Oct 2026
Updated9 Oct 2026
First seen5 Oct 2026
Track software like this
Free during beta