Arbitrary File Access Vulnerability in Atlassian Products
CVE-2026-21589

9.3CRITICAL

What is CVE-2026-21589?

This vulnerability affects several Atlassian Data Center products, enabling an unauthenticated remote attacker to gain access to specific files within the web application root directory. Essential exploitation requires prior knowledge of the exact file names and paths, with no ability to enumerate directory contents. In some configurations, the exposure of sensitive files could lead to severe repercussions.

Affected Version(s)

Bamboo Data Center All other versions

Bamboo Server All versions

Bitbucket Data Center All other versions

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.