Computers

Atlassian Patches Critical CVE-2026-21589 in Eight Data Center Products

Exploitation attempts against the authentication bypass were observed around two hours after WatchTowr published its technical analysis, SANS reported.

Atlassian has released fixed versions for CVE-2026-21589, a critical vulnerability that allows reading certain files without authentication, according to the security advisory the company published on October 5. The flaw carries a CVSS 4.0 score of 9.3 and affects the Data Center versions of Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd, as well as Crucible and Fisheye.

Atlassian said its Cloud products are already patched and require no further action from users.

WatchTowr published a technical analysis of the vulnerability on October 6, and roughly two hours later exploitation attempts were observed on honeypots. In a test environment, WatchTowr researchers read application credentials from the crowd.properties integration file and used them to create a user, which they then added to a Jira administrator group.

SANS Internet Storm Center confirmed in a report on October 7 that requests using the public exploit path had been reaching honeypots since the previous day.

Mitigation if patching is delayed

For organisations that cannot patch immediately, Atlassian advises limiting external internet access and applying WAF or product-specific request-blocking settings. The company did not specify a workaround beyond those measures.

Quick answers

Which Atlassian products are affected by CVE-2026-21589?

The Data Center versions of Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd, plus Crucible and Fisheye. Atlassian Cloud products are already patched.

How severe is CVE-2026-21589?

It has a CVSS 4.0 score of 9.3 and allows reading certain files without authentication.

What can administrators do if they cannot patch right away?

Atlassian advises limiting external internet access and applying WAF or product-specific request-blocking settings.

Source