CVE-2026-21589: unauthenticated file read on 8 Atlassian products
unauthenticated file read Jira Confluence Bitbucket Data Center

CVE-2026-21589: unauthenticated file read on 8 Atlassian products

Self-hosted Atlassian shops have a live problem, not a patch-when-convenient one. CVE-2026-21589 is a critical arbitrary file-access flaw, and scanning started within hours of a public technical write-up.

What happened

Atlassian published fixes on 5 October for a bug it rates CVSS 9.3. An unauthenticated attacker who already knows a file name and path can read that file from the web application root. The bug does not list directories.

On 7 October, Previdian told BleepingComputer its honeypots saw exploitation attempts within two hours of watchTowr's write-up. A scanner template is already public, so noisy probing should rise. In some identity-integrated setups, a successful read can be turned into administrator access. Cloud products are already patched.

Who is affected

Every unpatched self-managed Data Center instance of these products is in scope. Atlassian Cloud customers do not need to act on this advisory.

  • Bitbucket Data Center, fixed in 9.4.26, 10.2.8, and 10.5.1
  • Confluence Data Center, fixed in 9.2.26 and 10.2.19
  • Jira Software Data Center, fixed in 9.12.40, 10.3.26, and 11.3.12
  • Jira Service Management Data Center, fixed in 5.12.40, 10.3.26, and 11.3.12
  • Bamboo, Crowd, Crucible, and Fisheye Data Center are also affected

What to do now

Patch internet-facing Data Center instances today, or remove them from the public internet until the fix is on.

If Crowd is reachable from the application and SSO is in use, treat a vulnerable host as a possible identity compromise, not just a file read. Check for new admin users and unexpected group changes after the exposure window.

Source: BleepingComputer, Hackers exploit critical Atlassian flaw after public PoC release.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-91140: Progress DataDirect AI agent command injection
OpenAPI document to OS command in Copilot model generator