Arbitrary File Access Vulnerability in Atlassian Products
CVE-2026-21589
9.3CRITICAL
Key Information:
- Vendor
Atlassian
- Vendor
- CVE Published:
- 5 October 2026
What is CVE-2026-21589?
This vulnerability affects several Atlassian Data Center products, enabling an unauthenticated remote attacker to gain access to specific files within the web application root directory. Essential exploitation requires prior knowledge of the exact file names and paths, with no ability to enumerate directory contents. In some configurations, the exposure of sensitive files could lead to severe repercussions.
Affected Version(s)
Bamboo Data Center All other versions
Bamboo Server All versions
Bitbucket Data Center All other versions