PT-2026-106255 · Atlassian · Fisheye+7

CVE-2026-21589

·

Published

2026-10-05

·

Updated

2026-10-06

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Bitbucket Data Center versions 4.6.0 through 9.4.25 Bitbucket Data Center versions 10.2.0 through 10.2.7 Bitbucket Data Center versions 10.5.0 through 10.5.0 Confluence Data Center versions 5.10.0 through 9.2.25 Confluence Data Center versions 10.2.0 through 10.2.18 Crowd Data Center versions 2.11.0 through 6.3.6 Crowd Data Center versions 7.0.0 through 7.0.2 Crowd Data Center versions 7.1.0 through 7.1.0 Crowd Data Center versions 7.2.0 through 7.2.3 Jira Software Data Center versions 7.1.0 through 9.12.39 Jira Software Data Center versions 10.3.0 through 10.3.25 Jira Software Data Center versions 11.3.0 through 11.3.11 Jira Service Management Data Center versions 3.1.0 through 5.12.39 Jira Service Management Data Center versions 10.3.0 through 10.3.25 Jira Service Management Data Center versions 11.3.0 through 11.3.11 Bamboo Data Center versions 7.0.1 through 10.2.23 Bamboo Data Center versions 12.1.0 through 12.1.11 Crucible versions prior to 4.9.15 Fisheye versions prior to 4.9.15
Description An arbitrary file access flaw, specifically a path traversal issue, allows an unauthenticated remote attacker to read specific files within the web application root directory. Exploitation requires the attacker to have prior knowledge of the target file's exact name and path, as the issue does not allow for the enumeration or listing of directory contents. In certain configurations, this may lead to the exposure of sensitive files, such as configurations or templates, which could leak secrets and enable further compromise.
Recommendations Update Bitbucket Data Center to versions 9.4.26, 10.2.8, or 10.5.1. Update Confluence Data Center to versions 9.2.26 or 10.2.19. Update Crowd Data Center to versions 6.3.7, 7.0.3, 7.1.1, or 7.2.4. Update Jira Software Data Center to versions 9.12.40, 10.3.26, or 11.3.12. Update Jira Service Management Data Center to versions 5.12.40, 10.3.26, or 11.3.12. Update Bamboo Data Center to versions 10.2.24 or 12.1.12. Update Crucible to version 4.9.15. Update Fisheye to version 4.9.15. Restrict internet access or pull the instance off the public internet to minimize the risk of exploitation. Apply WAF or URL-rewrite mitigations if an immediate upgrade is not possible.

Fix

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-21589

Affected Products

Bamboo
Bitbucket
Confluence
Crowd
Crucible
Fisheye
Jira Service Management Server
Jira