Skip to content
ThreatCluster

Critical Arbitrary File Access Vulnerability in Atlassian Products Disclosed

First seen 6 Oct 2026, 18:03 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 19:02 UTC

On October 5, 2026, Atlassian disclosed CVE-2026-21589, a critical arbitrary file access vulnerability affecting multiple products including Bitbucket Data Center, Confluence Data Center, and Jira Software Data Center. All versions of these products are impacted, allowing unauthenticated attackers to access specific files within the web application root directory if they know the exact file name and path. The CVSS score for this vulnerability is 9.3, indicating its critical nature. Exploitation of this vulnerability does not allow for directory enumeration. CISA has not yet confirmed in the wild, but the vulnerability is significant enough to warrant immediate attention from security teams. Organizations using affected products are advised to apply patches as soon as they are available.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2019-07-26
CVE-2019-13990 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-01-17
CVE-2022-41903 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-05
CVE-2026-21589 published
Atlassian disclosed a critical arbitrary file access vulnerability affecting multiple products.
Confluence.Atlassian

More articles in this cluster (2)

Following this threat?

Track CVE-2019-13990 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which Atlassian products are affected?
The vulnerability affects Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, and Jira Software Data Center.
What is the CVSS score of this vulnerability?
CVE-2026-21589 has a CVSS score of 9.3, indicating it is critical.
What should organizations do?
Organizations should monitor for patches and apply them as soon as they become available to mitigate the risk.