ComputersAI

Atlassian Patches Critical File-Access Flaw in Data Center Products

CVE-2026-21589 affects self-hosted Confluence, Jira, Bitbucket and other Data Center products; cloud customers are already patched.

Atlassian has disclosed a critical arbitrary file-access vulnerability tracked as CVE-2026-21589 and released patched versions of the affected products, according to BleepingComputer.

The flaw affects self-hosted Data Center products, including Confluence, Jira, Bitbucket, Bamboo, Crowd, Crucible and Fisheye.

According to Atlassian, an unauthenticated attacker can access specific files in the web application root directory if they know the exact file name and path. The vulnerability does not allow attackers to enumerate or list directory contents.

Atlassian said it has no evidence that CVE-2026-21589 is being exploited in attacks.

Cloud customers do not need to take action because Atlassian automatically patched those products.

Quick answers

What is CVE-2026-21589?

It is a critical arbitrary file-access vulnerability in Atlassian's self-hosted Data Center products, including Confluence, Jira, Bitbucket, Bamboo, Crowd, Crucible and Fisheye.

Do Atlassian Cloud customers need to patch?

No. Atlassian said it automatically patched cloud products, so cloud customers do not need to act.

Is CVE-2026-21589 being exploited?

Atlassian said it has no evidence that the vulnerability is being exploited in attacks.

Source