CVE-2026-21589: critical vulnerability in Atlassian Bitbucket Data Center
Published · Updated
85Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.3epss 1.8%
from disclosure to weapon1 days
Published on NVDOct 5
1st PoC+1d
VulnCheck+2d
exploitation probability
1.8%top 23% of all CVEs
observed exploitation
yesVulnCheck
12 public exploit(s)
This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Affected products
Atlassian · Bamboo Data CenterAtlassian · Bitbucket Data CenterAtlassian · Confluence Data CenterAtlassian · Crowd Data CenterAtlassian · Crucible Data CenterAtlassian · Fisheye Data CenterAtlassian · Jira Service Management Data CenterAtlassian · Jira Software Data Centerpublic PoCs found — 12
githubgithub.com/MarcusProgram/CVE-2026-21589★ 7githubgithub.com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589★ 6githubgithub.com/tc4dy/CVE-2026-21589-PoC-Exploit★ 6githubgithub.com/ynsmroztas/AtlasSniper★ 3githubgithub.com/BimBoxH4/CVE-2026-21589★ 0githubgithub.com/0xBlackash/CVE-2026-21589★ 0githubgithub.com/aduli198/CVE-2026-21589★ 0vulncheckvulncheck.com/xdb/966813b9dc55unverifiedvulncheckvulncheck.com/xdb/2739faa497e3unverifiedvulncheckvulncheck.com/xdb/5818e155dcddunverifiedvulncheckvulncheck.com/xdb/46cc1659236eunverifiedvulncheckvulncheck.com/xdb/9f37f10ae8f8unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — Atlassian Bitbucket Data Center
In the same product, most dangerous first.
References
https://github.com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589https://jira.atlassian.com/browse/BAM-26567https://jira.atlassian.com/browse/BSERV-20604https://jira.atlassian.com/browse/CONFSERVER-104488https://jira.atlassian.com/browse/CRUC-8741https://jira.atlassian.com/browse/CWD-6610https://jira.atlassian.com/browse/FE-7583https://jira.atlassian.com/browse/JRASERVER-79546https://jira.atlassian.com/browse/JSDSERVER-16809