Critical Arbitrary File Access Vulnerability in Atlassian Products Disclosed
Article Content
- •CVE-2026-21589 is a critical arbitrary file access vulnerability with a CVSS score of 9.3.
- •Affected products include Bitbucket Data Center, Confluence Data Center, and Jira Software Data Center.
- •Exploitation requires knowledge of specific file names and paths, but does not allow directory enumeration.
On October 5, 2026, Atlassian disclosed CVE-2026-21589, a critical arbitrary file access vulnerability affecting multiple products including Bitbucket Data Center, Confluence Data Center, and Jira Software Data Center. All versions of these products are impacted, allowing unauthenticated attackers to access specific files within the web application root directory if they know the exact file name and path. The CVSS score for this vulnerability is 9.3, indicating its critical nature. Exploitation of this vulnerability does not allow for directory enumeration. CISA has not yet confirmed in the wild, but the vulnerability is significant enough to warrant immediate attention from security teams. Organizations using affected products are advised to apply patches as soon as they are available.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2019-13990 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which Atlassian products are affected?
What is the CVSS score of this vulnerability?
What should organizations do?
Continue Reading
Critical Vulnerabilities in Atlassian Products Expose Systems to Remote Attacks Atlassian has released security patches addressing multiple vulnerabilities across its products, including Confluence, Jira, and Bamboo. Notably, CVE-2026-45674 poses a critical risk, allowing attackers to intercept connections via man-in-the-middle attacks. Other vulnerabilities, such as CVE-2026-54512 and…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…