Atlassian warns of critical file access flaw in datacenter products
Atlassian disclosed CVE-2026-21589, a 9.3-rated arbitrary file access vulnerability affecting datacenter versions of Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible and Fisheye. Patches are available; users who cannot upgrade immediately are advised to block external access to their instances.
- CVE-2026-21589 rated 9.3 allows unauthenticated arbitrary file access
- Affects datacenter versions of Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible and Fisheye
- Exploitation requires knowing the exact file path; directory listing is not possible
- Atlassian advises restricting internet access to instances until patched
Read next
Security