Atlassian has disclosed CVE-2026-21589, a critical arbitrary file-access flaw affecting multiple self-hosted Data Center products including Confluence, Jira, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye. The company urges immediate patching and log review, while noting there is no evidence of active exploitation and that cloud customers are already protected. #Atlassian #CVE-2026-21589 #Confluence #Jira #Bitbucket #Bamboo #Crowd #Crucible #Fisheye
Keypoints
- CVE-2026-21589 enables unauthenticated arbitrary file access in Atlassian Data Center products.
- The flaw affects self-hosted Confluence, Jira, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye versions released before the fixed updates.
- Exploitation requires knowledge of the exact file name and path, and does not allow directory listing.
- Atlassian recommends immediate patching, or temporary network restrictions and WAF/proxy or rewrite mitigations.
- Administrators should check access logs for traversal patterns and apply mitigation changes to every cluster node.