Atlassian Data Center flaw CVE-2026-21589 needs urgent fix
Atlassian has told administrators of its self-hosted Data Center products to patch a critical vulnerability right away. The flaw, tracked as CVE-2026-21589, lets an attacker who has not logged in read certain files from an affected installation.
The company published its advisory on 5 October 2026. It rated the bug 9.3 on the CVSS 4.0 scale, based on its own internal assessment.
Almost the whole Data Center lineup is affected
CVE-2026-21589 is an arbitrary file access vulnerability. It affects all versions of these products:
- Bitbucket Data Center
- Confluence Data Center
- Jira Software Data Center
- Jira Service Management Data Center
- Bamboo Data Center
- Crowd Data Center
- Crucible and Fisheye
