Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589)
Attackers who know where to look can read files from Atlassian Data Center installations without logging in, the company has warned.

About CVE-2026-21589
CVE-2026-21589, a critical arbitrary file access vulnerability with a 9.3 CVSS score, affects all versions of Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.
Atlassian calculated the CVSS 4.0 score through its internal assessment and published the advisory on 5 October 2026.
“This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions,” reads the advisory.
“In some configurations, there may be sensitive files present that increase your risk,” Atlassian noted.
On the positive side, an attacker has to know the exact name and path of the target file to exploit it, and cannot use it to list or enumerate directory contents.
According to the company, the affected cloud products have been patched, its investigation found no evidence of exploitation, and customers using them do not need to take any action.
Fixes and temporary mitigations
Atlassian urges administrators to immediately upgrade each affected installation to a fixed version or to the latest release. The fixed versions are:
- Bitbucket Data Center 9.4.26, 10.2.8 and 10.5.1
- Confluence Data Center 9.2.26 and 10.2.19
- Jira Software Data Center and Jira Service Management Data Center 10.3.26 and 11.3.12 (also 9.12.40 for Jira Software and 5.12.40 for Jira Service Management)
- Bamboo Data Center 10.2.24 and 12.1.12
- Crowd Data Center 6.3.7, 7.0.3, 7.1.7 and 7.2.4
- Crucible and Fisheye 4.9.15
Atlassian recommends taking affected instances off the internet, if possible.
“Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action.”
The company has also published three temporary mitigations.
Atlassian cannot confirm whether customers’ instances have been affected and advises them to have their security teams check all affected instances for evidence of compromise.
The advisory does not mention whether the flaw has been exploited against Data Center instances, or who discovered it.