Skip to content
CVE-2026-21589 Affects Jira, Confluence, and Bitbucket

CVE-2026-21589 Affects Jira, Confluence, and Bitbucket

First seen 7 Oct 2026, 14:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 14:28 UTC
  • •CVE-2026-21589 is a critical vulnerability with a CVSS score of 9.3.
  • •Affected products include Jira, Confluence, and Bitbucket, with specific versions listed.
  • •A proof-of-concept for exploitation was released on October 7, 2026.

CVE-2026-21589, published on October 5, 2026, is an arbitrary file read vulnerability affecting Jira, Confluence, and Bitbucket. The vulnerability has a CVSS score of 9.3, indicating its severity. A proof-of-concept (PoC) for exploiting this vulnerability was released on October 7, 2026. The affected versions include various releases of Jira Software, Jira Service Management, Confluence Data Center, and Bitbucket Data Center. Detection scripts have been developed to check for vulnerabilities in these products. The articles report that attempts to exploit the vulnerability have been made, but responses indicate that some instances may not be vulnerable. Administrators are urged to check their systems against the provided detection scripts and apply patches as necessary.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-05
CVE-2026-21589 published
CVE-2026-21589 is disclosed as a critical arbitrary file read vulnerability affecting multiple Atlassian products.
Sploitus
2026-10-07
Proof-of-concept released
A proof-of-concept for CVE-2026-21589 was made public, enabling potential exploitation of the vulnerability.
github.com

More articles in this cluster (2)

Following this threat?

Track WatchTowr and CVE-2026-21589 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
Affected versions include Jira Software Data Center 9.12.40, 10.3.26, 11.3.12; Confluence Data Center 9.2.26, 10.2.19; and Bitbucket Data Center 9.4.26, 10.2.8, 10.5.1.
Is there a patch available?
Yes, patched versions have been released according to vendor advisories, and administrators should update their systems.
How can I check if my instance is vulnerable?
You can use the detection artifact generator script provided by Watch Towr to check if your Jira, Confluence, or Bitbucket instance is vulnerable.