What it is
CVE-2026-21589 is an unauthenticated vulnerability affecting Atlassian Bamboo Data Center and 7 other products. This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data...
Vulnerability report
Bamboo Data Center
Atlassian / Bamboo Data Center · All other versions
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-21589 is an unauthenticated vulnerability affecting Atlassian Bamboo Data Center and 7 other products. This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data...
Is it exploited?
Yes. Previdian sensors observed exploitation attempts with confirmed confidence. Also confirmed by third-party sources.
Who is affected?
Atlassian / Bamboo Data Center all other versions.
What should we do?
Patch immediately, validate internet-facing exposure, and monitor for matching requests.
Overview
This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents.
In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Previdian
Previdian independently recorded this as exploited after first seeing it in honeypot sensors.
Previdian sensor
Previdian first observed exploitation attempts targeting this vulnerability in our honeypot sensors.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Previdian Sensors First | 2026-10-06 21:55 UTC |
| BleepingComputer | 2026-10-07 13:21 UTC |
Operational indicators for this CVE are listed under Detection.
Sensor telemetry
Previdian sensors recorded exploitation attempts targeting this vulnerability. The cards and chart show volume, unique attackers, and daily activity.
36
Attempts observed
6
Unique attacker IPs
4
Attacker countries
CA · JP · TR · US
3
Sensors observed
CVE-2026-21589 exploitation attempts over the last 7 days
Daily events observed by Previdian sensors
Updated 07 Oct 2026
First observed 06 Oct 2026 · Last observed 07 Oct 2026
Pro adds sensor region and window summaries. Enterprise adds raw IPs, paths, User-Agents, and payloads.
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
Nuclei template detected 07 Oct 2026.
View Nuclei template (opens in new tab)Previdian virtual patch guidance is available for this CVE.
Attacker IP indicators observed · available in Pro and Enterprise.
Sensor-derived attacker IP indicators are available to Pro and Enterprise accounts under Detection and through the Pro API.
Learn about Pro API accessScanner and exploit-framework references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-21589.yaml | 07 Oct 2026 |
Compensating WAF rules for this CVE.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to Previdian Enterprise users.
Risk and context
CVSS v4.0
Potential damage if exploited. Separate from whether attackers are using it.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
EPSS
0.7%
Estimated chance of exploitation in the next 30 days. Previdian's warning comes from evidence, not this score.
Recent mention · BleepingComputer
A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attacks that do not require authentication. [...]
Read full advisoryRecent mention · BleepingComputer
Hackers exploit critical Atlassian flaw after public PoC releaseBleepingComputer · 07 Oct 2026
A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attacks that do not require authentication. [...]
Recent mention · Rapid7
CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian productsRapid7 · 07 Oct 2026
OverviewOn October 5, 2026, Atlassian published a security advisory for CVE-2026-21589, a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3. An unauthenticated remote attacker who knows a target file's exact name and path can access it within the application's web root; the vulnerability does not provide directory listing or...
Recent mention · The Hacker News
Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public DetailsThe Hacker News · 07 Oct 2026
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software
Recent mention · BleepingComputer
Atlassian warns of critical file-access flaw in Jira, ConfluenceBleepingComputer · 06 Oct 2026
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]
Recent mention · watchTowr
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)watchTowr · 06 Oct 2026
Welcome back to yet another episode of "security was taken seriously".Being who we are (and constantly being exposed to what we see…), we recognize we have been doomed to eternal damnation as we keep on watching security best practices crumble behind “secure by design”
Recent mention · TheRegister
Atlassian warns of critical file access flaw in its datacenter productsTheRegister · 06 Oct 2026
Tells users ‘action required’ – but maybe don’t make that action a Jira ticket, because it has this bug
Recent mention · The Hacker News
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsThe Hacker News · 06 Oct 2026
Swati KhandelwalOct 06, 2026Vulnerability / Web Security A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and listed a fixed version for each product. The web application root directory is the folder on the server that holds the web application itself. In...
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2026-10-07 09:03:00 UTC · 0 stars · AI assessment 90%
Atlassian Arbitrary File Read
github · Created 2026-10-06 18:21:50 UTC · 0 stars · AI assessment 90%
CVE-2026-21589 – Atlassian Data Center Unauth Arbitrary File Read (CVSS 9.3) | Red/Blue Team suite. 2 tools: Full Exploit (path traversal, WEB-INF read, credential harvest, 8 products, mass scan, SOCKS5/Tor, stealth) & SafeChecker (non-intrusive version audit, IoC guidance, JSON/CSV). Use Ethically, Stay Legal.
github · Created 2026-10-06 15:43:34 UTC · 3 stars · AI assessment 90%
github · Created 2026-10-06 10:40:59 UTC · 0 stars · AI assessment 85%
nuclei · Created Unknown
Timeline
13:21 UTC
Exploitation attested by an external source
10:03 UTC
Compensating WAF rule available to block exploitation
04:31 UTC
Scanner coverage available
20:52 UTC
Indicators of compromise recorded
20:52 UTC
Evidence-backed exploitation signal
10:40 UTC
Public proof-of-concept code published
05:20 UTC
Pro and Enterprise Watch users had 17 hours of early warning before Previdian confirmed it as a KEV.
21:30 UTC
Vulnerability disclosed publicly
00:00 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-21589
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-21589",
"confidence": "Confirmed",
"cvss_score": 9.3,
"cvss_estimated": false,
"epss_score": 0.00738,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": true
},
"sensor_telemetry": { "attempts": 36, "sensors": 3 }
}