Project Subscriptions
| Vendors | Products |
|---|---|
|
Atlassian
Subscribe
|
Bamboo Data Center
Subscribe
Bamboo Server
Subscribe
Bitbucket Data Center
Subscribe
Bitbucket Server
Subscribe
Confluence Data Center
Subscribe
Confluence Server
Subscribe
Crowd Data Center
Subscribe
Crucible
Subscribe
Crucible Data Center
Subscribe
Fisheye
Subscribe
Fisheye Data Center
Subscribe
Jira Server
Subscribe
Jira Service Management
Subscribe
Jira Service Management Data Center
Subscribe
Jira Software Data Center
Subscribe
Jira Software Server
Subscribe
|
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 07 Oct 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Remote Arbitrary File Access in Atlassian Data Center Products | |
| Weaknesses | CWE-200 CWE-284 |
Wed, 07 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Tue, 06 Oct 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Atlassian
Atlassian bamboo Data Center Atlassian bamboo Server Atlassian bitbucket Data Center Atlassian bitbucket Server Atlassian confluence Data Center Atlassian confluence Server Atlassian crowd Data Center Atlassian crucible Atlassian crucible Data Center Atlassian fisheye Atlassian fisheye Data Center Atlassian jira Server Atlassian jira Service Management Atlassian jira Service Management Data Center Atlassian jira Software Data Center Atlassian jira Software Server |
|
| Vendors & Products |
Atlassian
Atlassian bamboo Data Center Atlassian bamboo Server Atlassian bitbucket Data Center Atlassian bitbucket Server Atlassian confluence Data Center Atlassian confluence Server Atlassian crowd Data Center Atlassian crucible Atlassian crucible Data Center Atlassian fisheye Atlassian fisheye Data Center Atlassian jira Server Atlassian jira Service Management Atlassian jira Service Management Data Center Atlassian jira Software Data Center Atlassian jira Software Server |
Tue, 06 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. h3. Context This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. h3. Details: * The vulnerability must be addressed for affected versions of: Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.1, 7.2.4 Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 Crucible, fix versions 4.9.15 Fisheye, fix version 4.9.15 * Exploitation requires prior knowledge of the target file's exact name and path. * The vulnerability does not include the capability to enumerate or list directory contents. | This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents. |
Tue, 06 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-552 | |
| Metrics |
ssvc
|
Mon, 05 Oct 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Remote Arbitrary File Access in Atlassian Data Center Products | |
| Weaknesses | CWE-200 CWE-284 |
Mon, 05 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. h3. Context This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. h3. Details: * The vulnerability must be addressed for affected versions of: Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.1, 7.2.4 Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 Crucible, fix versions 4.9.15 Fisheye, fix version 4.9.15 * Exploitation requires prior knowledge of the target file's exact name and path. * The vulnerability does not include the capability to enumerate or list directory contents. | |
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: atlassian
Published:
Updated: 2026-10-06T18:09:09.752Z
Reserved: 2026-01-01T00:00:40.722Z
Link: CVE-2026-21589
Updated: 2026-10-06T13:51:25.309Z
Status : Awaiting Analysis
Published: 2026-10-05T22:16:58.423
Modified: 2026-10-06T19:18:14.447
Link: CVE-2026-21589
No data.
OpenCVE Enrichment
Updated: 2026-10-07T07:00:14Z