Description
h3. Summary

This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe.  

h3. Context

This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions.

h3. Details:

* The vulnerability must be addressed for affected versions of:
Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1
Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19
Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.1, 7.2.4
Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12
Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12
Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12
Crucible, fix versions 4.9.15
Fisheye, fix version 4.9.15
* Exploitation requires prior knowledge of the target file's exact name and path.
* The vulnerability does not include the capability to enumerate or list directory contents.
Published: 2026-10-05
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Arbitrary File Access (Unauthenticated)
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated remote attacker can read specific files located in the web application root directory of affected Atlassian products. The vulnerability requires prior knowledge of the exact file name and path, but it does not provide directory enumeration. This flaw can lead to disclosure of highly sensitive information such as configuration files, logs, or other internal documents, thereby compromising confidentiality and potentially enabling further attacks.

Affected Systems

The flaw affects a wide range of Atlassian Data Center and Server editions. Bitbucket Data Center versions starting at 4.6.0 are vulnerable until patch 9.4.26, 10.2.8 or 10.5.1. Confluence Data Center from 5.10.0 is affected until 9.2.26 or 10.2.19. Crowd Data Center from 2.11.0 requires upgrade to 6.3.7, 7.0.3, 7.1.1 or 7.2.4. Jira Software Data Center from 7.1.0 must be patched to 9.12.40, 10.3.26 or 11.3.12, as does Jira Service Management Data Center from 3.1.0. Bamboo Data Center from 7.0.1 needs at least 10.2.24 or 12.1.12. Crucible and Fisheye are fixed at 4.9.15.

Risk and Exploitability

The CVSS score of 9.3 classifies this as critical, and although the EPSS score is not available, the lack of a KEV listing does not diminish its inherent severity. The vulnerability is exploitable over the network without authentication, requiring only a crafted request that points to a known file path. As there is no directory listing capability, the attacker must have prior knowledge or guess the file location, limiting the attack surface relative to fully enumerative flaws. Nonetheless, the potential for confidential data leakage warrants immediate attention.

Generated by OpenCVE AI on October 5, 2026 at 22:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patches or upgrade to the specified fixed versions for all affected Atlassian Data Center and Server products.
  • If an immediate upgrade is not possible, block or restrict HTTP requests that reference paths under the web application root using a reverse proxy or web application firewall rule.
  • Review and tighten file‑system permissions and application configuration to ensure that only necessary directories are readable by the web server, mitigating the risk of future similar disclosures.

Generated by OpenCVE AI on October 5, 2026 at 22:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Arbitrary File Access in Atlassian Data Center Products
Weaknesses CWE-200
CWE-284

Mon, 05 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe.   h3. Context This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. h3. Details: * The vulnerability must be addressed for affected versions of: Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.1, 7.2.4 Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 Crucible, fix versions 4.9.15 Fisheye, fix version 4.9.15 * Exploitation requires prior knowledge of the target file's exact name and path. * The vulnerability does not include the capability to enumerate or list directory contents.
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published:

Updated: 2026-10-05T21:30:00.390Z

Reserved: 2026-01-01T00:00:40.722Z

Link: CVE-2026-21589

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T22:16:58.423

Modified: 2026-10-05T22:16:58.423

Link: CVE-2026-21589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T22:30:19Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control