Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-21589
Atlassian Bamboo Data Center — This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center,…
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H N N 9.3 .0175 77.2 —
AFFECTED
Product Versions Fixed
Bamboo Data Center All other versions – Patch version 10.2.24 and later
Bitbucket Data Center All other versions – Patch version 10.2.8 and later
Confluence Data Center All other versions – Patch version 10.2.19 and later
Crowd Data Center All other versions – Patch version 7.2.4 and later
Crucible Data Center All other versions – Patch version 4.9.15 and later
Fisheye Data Center All other versions – Patch version 4.9.15 and later
Jira Service Management Data Center All other versions – Patch version 11.3.12 and later
Jira Software Data Center All other versions – Patch version 11.3.12 and later
TIMELINE
Jan 1 Reserved by atlassian
Oct 5 Published (CNA: atlassian)
Oct 7 EXPLOIT PUBLISHED — CVE-2026-21589 (Atlassian Bamboo Data Center). Public exploit reference added.
Description
This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| January 1, 2026 | Reserved | Reserved by atlassian |
| October 5, 2026 | Published | Published (CNA: atlassian) |
| October 7, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-21589 (Atlassian Bamboo Data Center). Public exploit reference added. |
Affected
Affected products and packages — 8 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Atlassian | Bamboo Data Center | — | All other versions | Patch version 10.2.24 and later |
| Atlassian | Bitbucket Data Center | — | All other versions | Patch version 10.2.8 and later |
| Atlassian | Confluence Data Center | — | All other versions | Patch version 10.2.19 and later |
| Atlassian | Crowd Data Center | — | All other versions | Patch version 7.2.4 and later |
| Atlassian | Crucible Data Center | — | All other versions | Patch version 4.9.15 and later |
| Atlassian | Fisheye Data Center | — | All other versions | Patch version 4.9.15 and later |
| Atlassian | Jira Service Management Data Center | — | All other versions | Patch version 11.3.12 and later |
| Atlassian | Jira Software Data Center | — | All other versions | Patch version 11.3.12 and later |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-21589 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.