CVE- 2026-21589 is a critical unauthenticated arbitrary file access vulnerability disclosed by Atlassian on 5 October 2026, affecting eight Atlassian Data Centre products: Bitbucket Data Centre, Confluence Data Centre, Jira Service Management Data Centre, Jira Software Data Centre, Bamboo Data Centre, Crowd Data Centre, Crucible, and Fisheye.
An unauthenticated remote attacker who knows the exact name and path of a target file can read it from within the application’s web root, without the need for directory listing or enumeration. Atlassian assigns a CVSSv4 score of 9.3. Cloud deployments have been patched and require no action from customers; the issue affects on‑premises installations, including unsupported versions, until patched.
Rapid7’s coverage references a technical analysis showing a path traversal flaw in Atlassian’s web-resource handling, where double-colon sequences can be misinterpreted as path separators, enabling access to the resource-loading code and exfiltration of arbitrary files from the web root. Demonstrations indicated the ability to read files across the application, with credentials exposed in a WEB-INF/classes/crowd[.]properties file in an Jira‑configured Crowd deployment.
Atlassian’s guidance recommends upgrading to the fixed releases: Bitbucket Data Centre 9.4.26, 10.2.8, 10.5.1; Confluence Data Centre 9.2.26, 10.2.19; Jira Service Management Data Centre 5.12.40, 10.3.26, 11.3.12; Jira Software Data Centre 9.12.40, 10.3.26, 11.3.12; Bamboo Data Centre 10.2.24, 12.1.12; Crowd Data Centre 6.3.7, 7.0.3, 7.1.7, 7.2.4; Crucible 4.9.15; Fisheye 4.9.15.
Organisations should isolate affected systems from the internet or restrict external access if patching cannot be completed immediately, monitor access logs for exploitation attempts, and follow Atlassian’s guidance on URL-decoding and log analysis.