CVE-2026-21589 Affects Jira, Confluence, and Bitbucket
Article Content
- •CVE-2026-21589 is a critical vulnerability with a CVSS score of 9.3.
- •Affected products include Jira, Confluence, and Bitbucket, with specific versions listed.
- •A proof-of-concept for exploitation was released on October 7, 2026.
CVE-2026-21589, published on October 5, 2026, is an arbitrary file read vulnerability affecting Jira, Confluence, and Bitbucket. The vulnerability has a CVSS score of 9.3, indicating its severity. A proof-of-concept (PoC) for exploiting this vulnerability was released on October 7, 2026. The affected versions include various releases of Jira Software, Jira Service Management, Confluence Data Center, and Bitbucket Data Center. Detection scripts have been developed to check for vulnerabilities in these products. The articles report that attempts to exploit the vulnerability have been made, but responses indicate that some instances may not be vulnerable. Administrators are urged to check their systems against the provided detection scripts and apply patches as necessary.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track WatchTowr and CVE-2026-21589 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions are affected?
Is there a patch available?
How can I check if my instance is vulnerable?
Continue Reading
Critical CVE-2026-21589 Vulnerability in Atlassian Data Center Products On October 5, 2026, Atlassian disclosed CVE-2026-21589, a critical arbitrary file access vulnerability with a CVSS score of 9.3. This flaw affects eight self-hosted Data Center products, including Jira Software, Confluence, and Bitbucket, allowing unauthenticated attackers to read specific files within the web…
Critical Arbitrary File Access Vulnerability in Atlassian Products Disclosed On October 5, 2026, Atlassian disclosed CVE-2026-21589, a critical arbitrary file access vulnerability affecting multiple products including Bitbucket Data Center, Confluence Data Center, and Jira Software Data Center. All versions of these products are impacted, allowing unauthenticated attackers to access specific…