Image: rapid7.com · rights & removal
Executive Summary
A critical arbitrary file access vulnerability, CVE-2026-21589, was disclosed by Atlassian on October 5, 2026, affecting eight products including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. The vulnerability has a CVSSv4 score of 9.3. An unauthenticated remote attacker with knowledge of a target file's name and path can access files within the application's web root, without directory listing or enumeration capabilities. Affected Atlassian Cloud products are already patched.
Technical analysis by watchTowr Labs identified a path traversal vulnerability stemming from double-colon (::) sequences in web-resource handling that can act as path separators during request processing. This allows traversal components to reach resource-loading code, enabling the reading of arbitrary files within the application's web root. Exploitation could potentially expose application credentials if Crowd Data Center is deployed with Jira and network access is available. Organizations are strongly advised to upgrade to the listed fixed versions provided by Atlassian.
Facts Only
* CVE-2026-21589 was published by Atlassian on October 5, 2026.
* The vulnerability affects Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye.
* The vulnerability has a CVSSv4 score of 9.3.
* An unauthenticated remote attacker can access files within the application's web root if they know the file name and path.
* Atlassian advisory treats all versions before fixed releases as affected.
* watchTowr Labs identified a path traversal vulnerability related to double-colon (::) sequences in web-resource handling.
* Exploitation could read files throughout the application web root, though traversal outside the Tomcat context was not demonstrated.
* Mitigation involves upgrading to specific fixed versions for each affected product.
* Specific fixed versions include those listed for Bitbucket Data Center (9.4.26, 10.2.8, 10.5.1), Confluence Data Center (9.2.26, 10.2.19), and others.
* Mitigations include patching or implementing specific Web Application Firewall rules, Tomcat RewriteValve mitigations, and URL rewrite rules.
Full Take
From the original · Rapid7 Blog
Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589, a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3.Read the full story at rapid7.com
Sentinel — Human
This text reads like a synthesized security advisory compiled from primary technical sources, demonstrating a high degree of factual grounding rather than generic AI output.
