BreakingCyber Security
Critical Unauthenticated File Access Flaw Hits Multiple Atlassian Data Center Products
Atlassian disclosed CVE-2026-21589, a critical (CVSS 9.3) arbitrary file access vulnerability affecting Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd Data Center, Crucible and Fisheye. An unauthenticated attacker who knows a file's exact name and path can access it within the web application root, though directory listing is not possible. CERT-EU urges immediate patching, starting with internet-facing instances, and checking access logs for exploitation signs. Atlassian Cloud products are already patched, and no exploitation has been found so far.