Atlassian CVE-2026-21589: Critical File Access Vulnerability Affects 8 Data Center Products
RedSide Security October 06, 2026 CVE 1 views
Atlassian has disclosed critical vulnerability CVE-2026-21589 affecting eight self-hosted Data Center products, allowing unauthenticated attackers to read specific files from application root directories. Rated CVSS 9.3, the flaw affects Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye, with Atlassian urging customers to patch immediately.