Atlassian Patches Unauthenticated File Access Flaw Across Eight Data Center Products (CVE-2026-21589)
Scope: Atlassian Data Center products, including Jira, Confluence, Bitbucket, Bamboo, Crowd, FishEye, and Crucible, all versions before the fixed releases
Severity: Red
CVE-2026-21589 (CVSS 9.3) lets an unauthenticated attacker pull a specific file out of the web application root directory in any affected Data Center product. The catch, and the reason it has not turned into mass exploitation yet, is that the attacker needs to already know the exact file name and path. It does not let them browse or list what is there. That said, the kind of file names involved in setups like these are often predictable, config files, log files, known plugin paths, so knowing the target is a smaller hurdle than it sounds. Atlassian says it has no evidence of exploitation so far, but researchers at watchTowr point out that this exact class of flaw, arbitrary file access, has been used by ransomware groups and state-backed attackers before, and that eight other Atlassian flaws already sit on CISA's exploited list. Any organisation running Jira, Confluence, Bitbucket, or the other named products on Data Center must upgrade to the fixed release for that product now and check access logs for the traversal patterns in Atlassian's bulletin.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.