# Atlassian Data Center critical unauthenticated arbitrary file access vulnerability (CVE-2026-21589) across Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible and Fisheye

> Atlassian disclosed CVE-2026-21589 (CVSS 4.0 score 9.3), an unauthenticated arbitrary file access flaw that lets a remote attacker read files within the web application root of eight Data Center / self-managed products. No in-the-wild exploitation, public PoC or CISA KEV listing was reported at disclosure; Atlassian Cloud was patched before disclosure.

- **Published:** 2026-10-06T00:00:00Z
- **Last reviewed:** 2026-10-10T10:44:41.128Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2966
- **ID:** TL-2026-2966
- **Severity:** CRITICAL (CVSS 9.3)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 46 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-21589

## Description

CVE-2026-21589 is an arbitrary file access (path traversal class) vulnerability affecting Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. Atlassian's advisory (published 2026-10-05) states that an unauthenticated attacker can access specific files within the web application root directory. Exploitation requires prior knowledge of the target file's exact name and path; the flaw provides no directory listing or enumeration capability, which limits blind exploitation but does not help if the attacker targets well-known product file paths.

The CVSS v4.0 vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H (9.3 Critical): network reachable, low complexity, no privileges, no user interaction, high confidentiality impact on the vulnerable system and high impact on subsequent systems. Atlassian did not assign a CWE in its advisory or the CVE record; secondary analysis (The Hacker News, The CyberSec Guru) classifies it as CWE-22 path traversal, which is an analyst assessment rather than a vendor statement. Atlassian states all versions of the listed products are affected until upgraded to the fixed releases. Atlassian Cloud instances were already patched before disclosure and Atlassian reports no evidence of active exploitation; it also states it cannot confirm whether any given customer instance was affected.

Because the mitigation logic blocks requests with '..' adjacent to '/', '\' or '::' (including URL-encoded forms up to two levels), the exploitation pattern is traversal sequences in the request path. Secondary reporting notes that the files potentially exposed on such platforms include configuration files, credentials/API keys, database connection strings and CI/CD definitions; this is a risk characterization from the reporting, not a confirmed exploited outcome. Reporting also draws a parallel with CVE-2021-26086 (a Jira path traversal added to CISA KEV on 2024-11-12), suggesting these products are historically attractive targets once details circulate.

Atlassian published three temporary mitigations (not a substitute for patching): (1) a WAF / reverse-proxy rule for all eight products, (2) a Tomcat RewriteValve configuration for Confluence, Jira Software, Jira Service Management, Bamboo and Crowd (restart required, every cluster node), and (3) urlrewrite.xml rules for Bitbucket (every node, mirror and mirror farm node). Defenders can hunt historical access logs by URL-decoding requests (up to twice) and searching for '..' adjacent to path separators, or by running the block pattern against raw log lines. Instances that cannot be patched or mitigated should be taken offline.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1190 Exploit Public-Facing Application
- T1005 Data from Local System
- T1213 Data from Information Repositories
- T1552.001 Unsecured Credentials: Credentials In Files
- T1078 Valid Accounts
- T1136 Create Account
- T1098 Account Manipulation
- T1583.003 Acquire Infrastructure
- T1588.005 Obtain Capabilities: Exploits
- T1592 Gather Victim Host Information
- T1552 Unsecured Credentials
- T1083 File and Directory Discovery
- T1592.002 Gather Victim Host Information

## Sources

- [Atlassian security advisory: CVE-2026-21589 arbitrary file access vulnerability impacts multiple products](https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html)
- [CVE-2026-21589 CVE record](https://www.cve.org/CVERecord?id=CVE-2026-21589)
- [NVD API record for CVE-2026-21589](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-21589)
- [Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589)](https://www.helpnetsecurity.com/2026/10/06/atlassian-data-center-cve-2026-21589/)
- [Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products](https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html)
- [CVE-2026-21589: Critical Atlassian Flaw Exposes Sensitive Files](https://thecybersecguru.com/exploits/cve-2026-21589-atlassian-vulnerability/)
- [Critical Path Traversal in Atlassian Data Center Exposes Development Infrastructure](https://forkast.news/critical-path-traversal-in-atlassian-data-center-exposes-development-infrastructure/)
- [Critical CVE-2026-21589 Vulnerability Exposes Atlassian Data Center Products to Unauthenticated File Disclosure](https://www.rescana.com/post/critical-cve-2026-21589-vulnerability-exposes-atlassian-data-center-products-to-unauthenticated-file-disclosure)
- [Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products](https://cybersecuritynews.com/atlassian-patches-critical-vulnerabilities/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2966
