boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-21589

Atlassian Bamboo Data Center — This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center,…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    9.3   .0175   77.2     —
AFFECTED
  Product                              Versions              Fixed
  Bamboo Data Center                   All other versions –  Patch version 10.2.24 and later
  Bitbucket Data Center                All other versions –  Patch version 10.2.8 and later
  Confluence Data Center               All other versions –  Patch version 10.2.19 and later
  Crowd Data Center                    All other versions –  Patch version 7.2.4 and later
  Crucible Data Center                 All other versions –  Patch version 4.9.15 and later
  Fisheye Data Center                  All other versions –  Patch version 4.9.15 and later
  Jira Service Management Data Center  All other versions –  Patch version 11.3.12 and later
  Jira Software Data Center            All other versions –  Patch version 11.3.12 and later
TIMELINE
  Jan 1   Reserved by atlassian
  Oct 5   Published (CNA: atlassian)
  Oct 7   EXPLOIT PUBLISHED — CVE-2026-21589 (Atlassian Bamboo Data Center). Public exploit reference added.
CWE-552 · CNA: atlassian · CVSS v4.0 · 9 references · NVD status: Awaiting Analysis

Description

This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
January 1, 2026ReservedReserved by atlassian
October 5, 2026PublishedPublished (CNA: atlassian)
October 7, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-21589 (Atlassian Bamboo Data Center). Public exploit reference added.

Affected

Affected products and packages — 8 rows
VendorProduct / PackageEcosystemVersion introducedFixed
AtlassianBamboo Data Center—All other versionsPatch version 10.2.24 and later
AtlassianBitbucket Data Center—All other versionsPatch version 10.2.8 and later
AtlassianConfluence Data Center—All other versionsPatch version 10.2.19 and later
AtlassianCrowd Data Center—All other versionsPatch version 7.2.4 and later
AtlassianCrucible Data Center—All other versionsPatch version 4.9.15 and later
AtlassianFisheye Data Center—All other versionsPatch version 4.9.15 and later
AtlassianJira Service Management Data Center—All other versionsPatch version 11.3.12 and later
AtlassianJira Software Data Center—All other versionsPatch version 11.3.12 and later

Weaknesses

CWE-552

References (9)

Related

Authoritative record: CVE-2026-21589 at cve.org

Vendors: atlassian

Weaknesses: CWE-552

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-21589 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.