Self-hosted Atlassian: a file can be read without an account, if the path is already known
On 7 October 2026, CERT-EU published advisory 2026-015. CVE-2026-21589 can expose a file in the web root when the name and path are already known, with no account. Cloud is already patched. In NVD, the CISA coordinator marks exploitation as none.

Original AI-generated illustration · SecuFocus
At a glance
Key points
If you do not run these products, the advisory does not change your evening. If they can be reached from the Internet, the update comes first.
What changed
On 7 October 2026, CERT-EU published advisory 2026-015. The page also shows a version 1.0 dated 6 October. The advisory says Atlassian published an arbitrary file access flaw on 5 October. It affects Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.
CVE-2026-21589. The advisory repeats a CVSS score of 9.3. An unauthenticated attacker can read specific files in the web application root. They must already know the file name and path. The flaw does not let them list a directory. CERT-EU notes, citing Atlassian, that some configurations hold sensitive files, which raises the risk.
NVD published the record on 5 October 2026 at 22:16 UTC, and modified it on 6 October at 19:18 UTC. The status shown is Awaiting Analysis. The description repeats the same mechanism. The 9.3 score comes from Atlassian, as CVSS 4.0, marked Secondary. The CISA coordinator, in the NVD SSVC data on 6 October at 18:08 UTC, marks exploitation as none, and automatable as no.
The version ranges, kept separate
CERT-EU says every version earlier than the fixes below is affected. NVD adds a lower bound for several products. Crucible and Fisheye do not have one in the record we read. The cell says not documented, not zero.
Atlassian, as cited by CERT-EU, says affected Cloud products are already patched, and that its investigation found no evidence of exploitation.
Scroll the table sideways to read every column.
| Product | Fixed versions | Lower bound read on NVD |
|---|---|---|
| Bitbucket Data Center | 9.4.26, 10.2.8, 10.5.1 | 4.6.0 |
| Confluence Data Center | 9.2.26, 10.2.19 | 5.10.0 |
| Jira Service Management Data Center | 5.12.40, 10.3.26, 11.3.12 | 3.1.0 |
| Jira Software Data Center | 9.12.40, 10.3.26, 11.3.12 | 7.1.0 |
| Bamboo Data Center | 10.2.24, 12.1.12 | 7.0.1 |
| Crowd Data Center | 6.3.7, 7.0.3, 7.1.7, 7.2.4 | 2.11.0 |
| Crucible | 4.9.15 | not documented |
| Fisheye | 4.9.15 | not documented |
What we did not check
We do not have a Bitbucket, Confluence or Jira instance. We did not test the fix, or a firewall rule. “No evidence of exploitation” is Atlassian’s sentence as repeated by CERT-EU, plus the CISA coordinator’s SSVC option none. It is not a SecuFocus test. The versions come from CERT-EU and NVD. The vendor page is not cited here.
The choice
If you do not administer these products, there is nothing to install. Cloud, according to the advisory, is already patched.
If a Data Center, Crucible or Fisheye instance can be reached from the Internet, including behind a login page, CERT-EU asks you to move to a fixed version, starting with exposed instances. If you have to wait, take the instance off the Internet, or apply the rule described in the advisory. The exact snippets, and the instruction to back up before the local options, stay on the CERT-EU page. This note does not replay them.
Then look at the access logs. The advisory suggests decoding each line, or searching for the pattern it publishes. If a compromise is suspected, it asks you to investigate, rotate secrets that may have been read, and contact the relevant authority.
Check and explore
Sources for this article
Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.
- NVD, CVE-2026-21589 ↗nvd.nist.gov ·
This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.
Cite this article
Keep this reference with the article when you save or share it.