CVE-2026-21589 lets attackers read files in 8 Atlassian products
Unauthenticated file read in self-hosted Data Center

CVE-2026-21589 lets attackers read files in 8 Atlassian products

Atlassian published a critical advisory on 5 October for CVE-2026-21589, an arbitrary file access bug in eight self-hosted products. Cloud customers do not need to act. Data Center and some Server installs do.

What happened

An attacker who is not logged in can read a specific file inside the product's web application root, if they already know the exact name and path. The bug does not list directories. Atlassian rates it 9.3 on CVSS 4.0.

Risk rises where someone has parked backups, configuration, or secrets in that web root. Atlassian said some configurations have sensitive files there. It has not reported exploitation.

Affected products are Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. All versions before the fixed release are in scope, including some end-of-life lines that have no fix.

Who is affected

  • Self-hosted Data Center: Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd.
  • Crucible and Fisheye, fixed only at 4.9.15.
  • Internet-facing instances are the priority. Cloud is already patched.

What to do now

Patch to a fixed version this week, or remove the instance from the internet until you can. Atlassian said public instances, including those that require login, should be restricted from external access until patched.

Fixed lines include Jira Software Data Center 9.12.40, 10.3.26 and 11.3.12; Confluence Data Center 9.2.26 and 10.2.19; Bitbucket Data Center 9.4.26, 10.2.8 and 10.5.1. Match the product line in the advisory before you upgrade.

Source: Atlassian security advisory, 5 October 2026. CVE-2026-21589 advisory.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Denmark CPR breach exposes 8.8 million identity records
Lawful company lookup abused across the national register