Atlassian CVE-2026-21589: unauthenticated file access, CVSS 9.3
Arbitrary file access in eight self-hosted Atlassian Data Center products

Atlassian CVE-2026-21589: unauthenticated file access, CVSS 9.3

Atlassian patched CVE-2026-21589, a critical arbitrary-file-access bug scored CVSS 9.3. An unauthenticated attacker who already knows a file name and path can read that file from the web application root. The bug does not let the attacker list the directory.

What happened

Atlassian and WatchTowr both say there is no evidence of exploitation in the wild. That is not a reason to wait. Eight Atlassian flaws are already on CISA's Known Exploited Vulnerabilities list, and this class of bug has been used by ransomware crews and espionage groups against collaboration servers before.

WatchTowr's Yordan Ganchev warned that sites using Crowd for single sign-on should be especially careful. Authentication details can sit in plaintext at a predictable path. If Crowd is reachable, that file is enough to mint an administrator.

Who is affected

Self-hosted Data Center and server products, not Atlassian Cloud. All versions of these eight products are in scope until the fixed build for that branch is installed:

  • Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1.
  • Confluence Data Center: 9.2.26, 10.2.19.
  • Jira Software Data Center: 9.12.40, 10.3.26, 11.3.12.
  • Jira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12.
  • Bamboo Data Center: 10.2.24, 12.1.12.
  • Crowd Data Center: 6.3.7, 7.0.3, 7.1.7, 7.2.4.
  • Crucible 4.9.15 and Fisheye 4.9.15.

What to do now

Patch the fixed build for each product, or remove the instance from the internet until that patch is on. Atlassian says public instances, including ones that already require a login, should be cut off from external access until you can act. If Crowd fronts SSO, treat that host as the priority.

Source: SecurityWeek, Atlassian Patches Critical Vulnerability Affecting 8 Products.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Nikkei Microsoft 365 account sent 9,000 phishing emails after takeover
Employee Google and Microsoft cloud mailboxes compromised