CVE Watchtower

← Back to CVE List

CVE-2026-21589NVD

Vulnerability Summary

h3. Summary

This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe.  

h3. Context

This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions.

h3. Details:

* The vulnerability must be addressed for affected versions of:
Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1
Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19
Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.1, 7.2.4
Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12
Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12
Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12
Crucible, fix versions 4.9.15
Fisheye, fix version 4.9.15
* Exploitation requires prior knowledge of the target file's exact name and path.
* The vulnerability does not include the capability to enumerate or list directory contents.
Severity Level
CRITICAL(9.3)
Published Date
Oct 5, 2026
Last Modified
Oct 5, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
N/A
CVSS v4.0 Base Metrics — Score 9.3 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)None
Availability (Vulnerable System)None
Confidentiality (Subsequent System)High
Integrity (Subsequent System)High
Availability (Subsequent System)High

Affected & Patched Versions

Affected Versions
  • Atlassian Bamboo Data Center >= All other versions
  • Atlassian Bamboo Server >= All versions
  • Atlassian Bitbucket Data Center >= All other versions
  • Atlassian Bitbucket Server >= All versions
  • Atlassian Confluence Data Center >= All other versions
  • Atlassian Confluence Server >= All versions
  • Atlassian Crowd Data Center >= All other versions
  • Atlassian Crowd Server >= All versions
  • Atlassian Crucible Data Center >= All other versions
  • Atlassian Crucible Server >= All other versions
  • Atlassian Fisheye Data Center >= All other versions
  • Atlassian Fisheye Server >= All other versions
  • Atlassian Jira Service Management Data Center >= All other versions
  • Atlassian Jira Service Management Server >= All other versions
  • Atlassian Jira Software Data Center >= All other versions
  • Atlassian Jira Software Server >= All other versions
Patched Versions
Not provided by cveorg for this CVE.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.