Atlassian published a critical advisory on 5 October for CVE-2026-21589, an arbitrary file access bug in eight self-hosted products. Cloud customers do not need to act. Data Center and some Server installs do.
What happened
An attacker who is not logged in can read a specific file inside the product's web application root, if they already know the exact name and path. The bug does not list directories. Atlassian rates it 9.3 on CVSS 4.0.
Risk rises where someone has parked backups, configuration, or secrets in that web root. Atlassian said some configurations have sensitive files there. It has not reported exploitation.
Affected products are Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. All versions before the fixed release are in scope, including some end-of-life lines that have no fix.
Who is affected
- Self-hosted Data Center: Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd.
- Crucible and Fisheye, fixed only at 4.9.15.
- Internet-facing instances are the priority. Cloud is already patched.
What to do now
Patch to a fixed version this week, or remove the instance from the internet until you can. Atlassian said public instances, including those that require login, should be restricted from external access until patched.
Fixed lines include Jira Software Data Center 9.12.40, 10.3.26 and 11.3.12; Confluence Data Center 9.2.26 and 10.2.19; Bitbucket Data Center 9.4.26, 10.2.8 and 10.5.1. Match the product line in the advisory before you upgrade.
Source: Atlassian security advisory, 5 October 2026. CVE-2026-21589 advisory.
Also on the blog
- Denmark CPR breach exposes 8.8 million identity records
- CVE-2026-63277: LibreOffice spreadsheet runs code with no macro warning
- CVE-2026-86360: Dell System Update path traversal to root
- ASOS push alerts claim a Snowflake compromise
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.