CVE-2026-21589: Atlassian Data Center file read at CVSS 9.3
unauthenticated file read in Jira, Confluence, Bitbucket, and Crowd

CVE-2026-21589: Atlassian Data Center file read at CVSS 9.3

Self-hosted Atlassian Data Center products have an unauthenticated file-read bug, CVE-2026-21589, scored CVSS 9.3. Attackers started probing it within hours of a public technical write-up.

What happened

Atlassian disclosed the issue on 5 October 2026. A remote attacker who already knows the exact path can read specific files inside the web application root. The bug does not list directory contents.

watchTowr published analysis and proof-of-concept code on 6 October. Previdian honeypots recorded exploitation attempts the same day. As of 8 October, Previdian had logged 190 attempts from 32 addresses in 10 countries. CISA has not added this CVE to the Known Exploited Vulnerabilities catalog. That is not a reason to wait.

The sharp case is Jira integrated with Crowd. The readable file can hold Crowd application credentials in plaintext. watchTowr used those credentials to create a user and place it in the Jira administrators group.

Who is affected

Atlassian Cloud is already patched. No Cloud customer action is required. Every listed self-hosted product, on all versions before the fixed builds, is in scope.

  • Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, and Crowd Data Center.
  • Crucible and Fisheye.
  • Highest practical risk: internet-facing Jira that trusts Crowd, because one properties file can become an admin account.

What to do now

Patch each self-hosted instance to a fixed version, or cut it off from the internet until you do.

  • Jira Software and Jira Service Management Data Center: 9.12.40, 10.3.26, or 11.3.12. Jira Service Management also has 5.12.40.
  • Confluence Data Center: 9.2.26 or 10.2.19. Bitbucket Data Center: 9.4.26, 10.2.8, or 10.5.1.
  • Bamboo Data Center: 10.2.24 or 12.1.12. Crowd Data Center: 6.3.7, 7.0.3, 7.1.7, or 7.2.4. Crucible and Fisheye: 4.9.15.
  • If Jira is integrated with Crowd and the instance was reachable, rotate the Crowd application credentials and review admin users created since 6 October.

Source: SecurityWeek, Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

AhsayCBS CVE-2026-105134: SYSTEM RCE, 5 organizations hit
unpatched Ahsay backup console webshell and XMRig