Atlassian told self-hosted customers to patch a critical file-read bug across eight Data Center products. CVE-2026-21589 scores 9.3 on CVSS 4.0. The advisory went out on 5 October 2026. Cloud customers are already patched.
What happened
An attacker with no login can read a specific file inside the web application root if they already know the exact name and path. They cannot list the directory. That limit matters, but it is not a control. Config files, keys, and install leftovers in that folder are enough when the path is known or guessable.
Atlassian says its cloud investigation found no evidence of exploitation. The advisory does not say the same for Data Center, and it does not name a discoverer. Treat internet-facing Data Center instances as exposed until they are upgraded.
Who is affected
Self-hosted Data Center builds below the fixed versions. Cloud needs no customer action.
- Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1
- Confluence Data Center: 9.2.26, 10.2.19
- Jira Software and Jira Service Management Data Center: 10.3.26 and 11.3.12, plus 9.12.40 and 5.12.40 on the older lines
- Bamboo 10.2.24 and 12.1.12; Crowd 6.3.7, 7.0.3, 7.1.7, 7.2.4; Crucible and Fisheye 4.9.15
What to do now
Upgrade each Data Center product to a fixed version, or take the instance off the public internet until you can. Atlassian is explicit: a login page is not a mitigation. After the upgrade, have someone who knows the install layout check the web root for files that should never have been readable.
Source: Help Net Security, 6 October 2026.
Also on the blog
- NetScaler CVE-2026-88779 (CVSS 8.7) crashes SAML appliances
- FortiMail CVE-2026-104286 (CVSS 9.8) file-write zero-day
- Exchange CVE-2026-96940: signed-in users can read other mailboxes
- Dell DSU CVE-2026-86360 (CVSS 9.6) root on PowerEdge updates
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.