Vulnerability report

Active exploitation observed Confirmed confidence Not in CISA KEV

CVE-2026-21589

Bamboo Data Center

Atlassian / Bamboo Data Center · All other versions

Severity
CVSS 9.3 · Critical
Confidence
Confirmed
Exploit status
Observed in sensors
EPSS
0.7%
First observed
06 Oct 2026
Last observed
07 Oct 2026

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2026-21589 is an unauthenticated vulnerability affecting Atlassian Bamboo Data Center and 7 other products. This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data...

Is it exploited?

Yes. Previdian sensors observed exploitation attempts with confirmed confidence. Also confirmed by third-party sources.

Who is affected?

Atlassian / Bamboo Data Center all other versions.

What should we do?

Patch immediately, validate internet-facing exposure, and monitor for matching requests.

Overview

Bamboo Data Center

This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents.

In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.

Atlassian Affected
Bamboo Data Center
All other versions
Atlassian Unaffected
Bamboo Data Center
Patch version 10.2.24 and later Patch version 12.1.12 and later
Atlassian Affected
Bitbucket Data Center
All other versions
Atlassian Unaffected
Bitbucket Data Center
Patch version 10.2.8 and later Patch version 10.5.1 and later Patch version 9.4.26 and later
Atlassian Affected
Confluence Data Center
All other versions
Atlassian Unaffected
Confluence Data Center
Patch version 10.2.19 and later Patch version 9.2.26 and later
Atlassian Affected
Crowd Data Center
All other versions
Atlassian Unaffected
Crowd Data Center
Patch version 7.2.4 and later Patch version 7.1.7 and later Patch version 7.0.3 and later Patch version 6.3.7 and later
Atlassian Affected
Crucible Data Center
All other versions
Atlassian Unaffected
Crucible Data Center
Patch version 4.9.15 and later
Atlassian Affected
Fisheye Data Center
All other versions
Atlassian Unaffected
Fisheye Data Center
Patch version 4.9.15 and later
Atlassian Affected
Jira Service Management Data Center
All other versions
Atlassian Unaffected
Jira Service Management Data Center
Patch version 11.3.12 and later Patch version 10.3.26 and later Patch version 5.12.40 and later
Atlassian Affected
Jira Software Data Center
All other versions
Atlassian Unaffected
Jira Software Data Center
Patch version 11.3.12 and later Patch version 10.3.26 and later Patch version 9.12.40 and later
Published
05 Oct 2026
Exploitation Reported
06 Oct 2026
Attack vector
Remote
Complexity
Low
Privileges
None
User interaction
None

Tags

nuclei_scanner

CVE References

Exploitation evidence

Why Previdian marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

Previdian

Recorded 06 Oct 2026

Previdian independently recorded this as exploited after first seeing it in honeypot sensors.

Active exploitation observed

Previdian sensor

First observed 06 Oct 2026

Previdian first observed exploitation attempts targeting this vulnerability in our honeypot sensors.

Proof of concept available

GitHub

Recorded 06 Oct 2026

Public scanner or PoC coverage increases practical exploitability.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the Previdian Pro API.

Learn about Pro API access
Source Added
Previdian Sensors First 2026-10-06 21:55 UTC
BleepingComputer 2026-10-07 13:21 UTC

Operational indicators for this CVE are listed under Detection.

Sensor telemetry

First-party evidence of exploitation activity

Previdian sensors recorded exploitation attempts targeting this vulnerability. The cards and chart show volume, unique attackers, and daily activity.

36

Attempts observed

6

Unique attacker IPs

4

Attacker countries

CA · JP · TR · US

3

Sensors observed

CVE-2026-21589 exploitation attempts over the last 7 days

Daily events observed by Previdian sensors

Updated 07 Oct 2026

0
0
0
0
0
6
30
1 Oct 2 Oct 3 Oct 4 Oct 5 Oct 6 Oct 7 Oct

First observed 06 Oct 2026 · Last observed 07 Oct 2026

Pro adds sensor region and window summaries. Enterprise adds raw IPs, paths, User-Agents, and payloads.

Start 14-day Pro trial

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
User-Agents
Callback hosts
17
13
0

Request targets and User-Agents available in Pro. Callback host details available in Enterprise.

Virtual patch status

Previdian virtual patch guidance is available for this CVE.

AWS WAF Cloudflare ModSecurity

Attacker IP Indicators

Attacker IP indicators observed · available in Pro and Enterprise.

Sensor-derived attacker IP indicators are available to Pro and Enterprise accounts under Detection and through the Pro API.

Learn about Pro API access

Scanner Artifacts

Scanner and exploit-framework references linked to this CVE.

Virtual Patch Detail

Compensating WAF rules for this CVE.

Available

Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to Previdian Enterprise users.

Risk and context

Severity, weaknesses, and research context

CVSS v4.0

9.3 Critical

Potential damage if exploited. Separate from whether attackers are using it.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H

EPSS

0.7%

Estimated chance of exploitation in the next 30 days. Previdian's warning comes from evidence, not this score.

Recent mention · BleepingComputer

Hackers exploit critical Atlassian flaw after public PoC release

A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attacks that do not require authentication. [...]

Read full advisory

All Mentions

Recent mention · BleepingComputer

Hackers exploit critical Atlassian flaw after public PoC release

BleepingComputer · 07 Oct 2026

A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attacks that do not require authentication. [...]

Recent mention · Rapid7

CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products

Rapid7 · 07 Oct 2026

OverviewOn October 5, 2026, Atlassian published a security advisory for CVE-2026-21589, a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3. An unauthenticated remote attacker who knows a target file's exact name and path can access it within the application's web root; the vulnerability does not provide directory listing or...

Recent mention · The Hacker News

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

The Hacker News · 07 Oct 2026

Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software

Recent mention · BleepingComputer

Atlassian warns of critical file-access flaw in Jira, Confluence

BleepingComputer · 06 Oct 2026

Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]

Recent mention · watchTowr

You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)

watchTowr · 06 Oct 2026

Welcome back to yet another episode of "security was taken seriously".Being who we are (and constantly being exposed to what we see…), we recognize we have been doomed to eternal damnation as we keep on watching security best practices crumble behind “secure by design”

Recent mention · TheRegister

Atlassian warns of critical file access flaw in its datacenter products

TheRegister · 06 Oct 2026

Tells users ‘action required’ – but maybe don’t make that action a Jira ticket, because it has this bug

Recent mention · The Hacker News

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

The Hacker News · 06 Oct 2026

Swati KhandelwalOct 06, 2026Vulnerability / Web Security A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and listed a fixed version for each product. The web application root directory is the folder on the server that holds the web application itself. In...

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

aduli198/CVE-2026-21589

github · Created 2026-10-07 09:03:00 UTC · 0 stars · AI assessment 90%

Atlassian Arbitrary File Read

tc4dy/CVE-2026-21589-PoC-Exploit

github · Created 2026-10-06 18:21:50 UTC · 0 stars · AI assessment 90%

CVE-2026-21589 – Atlassian Data Center Unauth Arbitrary File Read (CVSS 9.3) | Red/Blue Team suite. 2 tools: Full Exploit (path traversal, WEB-INF read, credential harvest, 8 products, mass scan, SOCKS5/Tor, stealth) & SafeChecker (non-intrusive version audit, IoC guidance, JSON/CSV). Use Ethically, Stay Legal.

MarcusProgram/CVE-2026-21589

github · Created 2026-10-06 15:43:34 UTC · 3 stars · AI assessment 90%

watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589

github · Created 2026-10-06 10:40:59 UTC · 0 stars · AI assessment 85%

Timeline

From disclosure to observed exploitation

  1. 13:21 UTC

    KEV confirmed by BleepingComputer

    Exploitation attested by an external source

  2. 10:03 UTC

    Virtual patch available

    Compensating WAF rule available to block exploitation

  3. 04:31 UTC

    Nuclei template available

    Scanner coverage available

  4. 20:52 UTC

    Indicators of compromise added (6)

    Indicators of compromise recorded

  5. 20:52 UTC

    Observed by Previdian sensors

    Evidence-backed exploitation signal

  6. 10:40 UTC

    Public PoC available

    Public proof-of-concept code published

  7. 05:20 UTC

    Added to the Previdian watchlist

    Pro and Enterprise Watch users had 17 hours of early warning before Previdian confirmed it as a KEV.

  8. 21:30 UTC

    CVE published

    Vulnerability disclosed publicly

  9. 00:00 UTC

    CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2026-21589

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2026-21589",
  "confidence": "Confirmed",
  "cvss_score": 9.3,
  "cvss_estimated": false,
  "epss_score": 0.00738,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": true
  },
  "sensor_telemetry": { "attempts": 36, "sensors": 3 }
}