CVE-2026-21589: unauthenticated file read on Atlassian Data Center
Jira Confluence Bitbucket arbitrary file access CVSS 9.3

CVE-2026-21589: unauthenticated file read on Atlassian Data Center

Atlassian Data Center customers have a live file-read problem. CVE-2026-21589 (CVSS 9.3) lets an unauthenticated attacker read specific files inside the web application root if they already know the exact name and path. Directory listing is not part of the bug. Exploitation attempts hit a honeypot network about two hours after public technical details landed.

What happened

Atlassian disclosed an arbitrary file-access flaw across self-hosted Data Center products. Cloud products were patched by the vendor. Researchers tied the bug to web-resource path handling that rewrites separator strings into directory traversal. A single request can pull files such as WEB-INF/web.xml from the application root.

Previdian reported 15 attempts from three IP addresses in Japan and the United States. On Crowd and Jira, a successful read of crowd.properties can expose Crowd credentials. Those credentials can be used to create users and promote a new account to Jira administrator.

Who is affected

Self-hosted Data Center installs of Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye on unfixed versions. Internet-facing instances are the immediate target. Internal instances still matter if an attacker already has a foothold on the network.

  • Bitbucket Data Center fixed in 9.4.26, 10.2.8, and 10.5.1
  • Confluence Data Center fixed in 9.2.26 and 10.2.19
  • Jira Software and Jira Service Management Data Center fixed in 5.12.40, 10.3.26, and 11.3.12 (JSM) and 9.12.40, 10.3.26, and 11.3.12 (Jira)
  • Bamboo, Crowd, Crucible, and Fisheye also have fixed builds

What to do now

Patch the fixed Data Center build today, or take the instance off the public internet until you do. If you cannot patch immediately, apply Atlassian's WAF or Tomcat RewriteValve mitigation and block the known resource path. After patching, review admin user creation, Crowd credential files, and authentication logs for new accounts you did not create.

Source: The Hacker News, 7 October 2026, Atlassian Data Center flaw draws exploitation attempts within two hours.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Langflow CVE-2026-0768: unauthenticated code execution under active scan
Langflow validate endpoint remote code execution