SecuFocus
BriefAnnouncements

Self-hosted Atlassian: a file can be read without an account, if the path is already known

On 7 October 2026, CERT-EU published advisory 2026-015. CVE-2026-21589 can expose a file in the web root when the name and path are already known, with no account. Cloud is already patched. In NVD, the CISA coordinator marks exploitation as none.

Illustration, not an Atlassian screenshot.

Original AI-generated illustration · SecuFocus

At a glance

Key points

If you do not run these products, the advisory does not change your evening. If they can be reached from the Internet, the update comes first.

What changed

On 7 October 2026, CERT-EU published advisory 2026-015. The page also shows a version 1.0 dated 6 October. The advisory says Atlassian published an arbitrary file access flaw on 5 October. It affects Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.

CVE-2026-21589. The advisory repeats a CVSS score of 9.3. An unauthenticated attacker can read specific files in the web application root. They must already know the file name and path. The flaw does not let them list a directory. CERT-EU notes, citing Atlassian, that some configurations hold sensitive files, which raises the risk.

NVD published the record on 5 October 2026 at 22:16 UTC, and modified it on 6 October at 19:18 UTC. The status shown is Awaiting Analysis. The description repeats the same mechanism. The 9.3 score comes from Atlassian, as CVSS 4.0, marked Secondary. The CISA coordinator, in the NVD SSVC data on 6 October at 18:08 UTC, marks exploitation as none, and automatable as no.

The version ranges, kept separate

CERT-EU says every version earlier than the fixes below is affected. NVD adds a lower bound for several products. Crucible and Fisheye do not have one in the record we read. The cell says not documented, not zero.

Atlassian, as cited by CERT-EU, says affected Cloud products are already patched, and that its investigation found no evidence of exploitation.

Scroll the table sideways to read every column.

ProductFixed versionsLower bound read on NVD
Bitbucket Data Center9.4.26, 10.2.8, 10.5.14.6.0
Confluence Data Center9.2.26, 10.2.195.10.0
Jira Service Management Data Center5.12.40, 10.3.26, 11.3.123.1.0
Jira Software Data Center9.12.40, 10.3.26, 11.3.127.1.0
Bamboo Data Center10.2.24, 12.1.127.0.1
Crowd Data Center6.3.7, 7.0.3, 7.1.7, 7.2.42.11.0
Crucible4.9.15not documented
Fisheye4.9.15not documented

What we did not check

We do not have a Bitbucket, Confluence or Jira instance. We did not test the fix, or a firewall rule. “No evidence of exploitation” is Atlassian’s sentence as repeated by CERT-EU, plus the CISA coordinator’s SSVC option none. It is not a SecuFocus test. The versions come from CERT-EU and NVD. The vendor page is not cited here.

The choice

If you do not administer these products, there is nothing to install. Cloud, according to the advisory, is already patched.

If a Data Center, Crucible or Fisheye instance can be reached from the Internet, including behind a login page, CERT-EU asks you to move to a fixed version, starting with exposed instances. If you have to wait, take the instance off the Internet, or apply the rule described in the advisory. The exact snippets, and the instruction to back up before the local options, stay on the CERT-EU page. This note does not replay them.

Then look at the access logs. The advisory suggests decoding each line, or searching for the pattern it publishes. If a compromise is suspected, it asks you to investigate, rotate secrets that may have been read, and contact the relevant authority.

Check and explore

Sources for this article

Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.

This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.

Cite this article

Keep this reference with the article when you save or share it.