CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products
Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589, a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd…
Sources
Vulnerabilities
Why this score
| Signal | Points |
|---|---|
| cvss critical — 9.3 | 20 |
| widely deployed | 15 |