type: cve · created: 2026-10-07 · updated: 2026-10-07 · tags: [cve] · confidence: medium · severity: critical · affected_sectors: [global] · au_impact: false
Atlassian disclosed CVE-2026-21589, a critical (9.3 / CVSS 4.0) flaw letting unauthenticated attackers read specific files from the web-application root of its Data Centre products — Jira Software, Confluence, Bitbucket, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-21589 |
| CVSS | 9.3 (CRITICAL) |
| Vendor / product | Atlassian |
| Reported | 2026-10-07 |