Summary
- CVE-2026-21589 carries a CVSS score of 9.3 and affects eight self-managed Atlassian product families.
- An unauthenticated attacker can access a specified file if its exact path and filename are known.
- Atlassian says its cloud services have been patched and it has found no evidence of exploitation.
Atlassian has released security updates across eight product families after identifying a critical vulnerability that can allow an unauthenticated attacker to access specified files on affected servers.
CVE-2026-21589 carries a CVSS score of 9.3 under Atlassian’s assessment. It affects Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.
An attacker exploiting the flaw needs to know the exact path and filename being targeted. Atlassian says the vulnerability does not allow directory contents to be listed, which limits the ability to discover unknown files through the flaw itself.
That condition narrows the route of attack without removing it. File locations can be predictable or become known from product documentation, common deployment patterns or information gathered elsewhere. The risk also depends on what individual organisations store within locations that the application can expose.
Atlassian has released corrected versions across the affected product lines and is directing organisations running self-managed deployments to update. Cloud versions affected by the underlying issue have already been patched by Atlassian.
Self-managed installations require local remediation
The division of responsibility is important because organisations running Atlassian software on their own infrastructure must perform the remediation themselves. They need to identify affected installations, assess the version in use and complete an upgrade through their existing change process.
The eight affected product families span development, collaboration, service management and supporting enterprise functions. A common vulnerability across that portfolio can therefore appear in different parts of an organisation rather than remaining confined to one application type.
Internet-facing systems deserve particular attention because an attacker does not need an existing internal foothold to send requests to them. Organisations unable to update immediately have to rely on the temporary mitigations Atlassian has documented until the fixed version can be deployed.
The requirement to know an exact path also affects investigation. Failed or successful requests for particular files may appear in access logs, while the absence of directory listing activity does not establish that an attacker never attempted to retrieve a known file.
Atlassian said its investigation had found no evidence of exploitation when the advisory was published. The critical severity rating describes the potential effect of the vulnerability and the conditions required to exploit it; it does not mean attackers have already used it against customers.
Ireland’s National Cyber Security Centre also highlighted the vulnerability in its alert stream, giving organisations another official signal to assess affected installations and apply the vendor’s fixes.
The possible consequence depends on the files present in each deployment. Atlassian does not state that every affected installation exposes credentials, source code or other particularly sensitive information, so those outcomes cannot be assumed from the vulnerability alone.
The confirmed risk is specific: vulnerable versions can return a specified file to an unauthenticated attacker who already knows its exact location. Fixed versions are available, Atlassian has updated the affected cloud services, and the company had not identified exploitation when it published its advisory.





