CVE-2026-21589: Path Traversal

Published Oct 5, 2026
·
Updated

h3. Summary

This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe.

h3. Context

This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions.

h3. Details:

The vulnerability must be addressed for affected versions of: Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.1, 7.2.4 Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 Crucible, fix versions 4.9.15 Fisheye, fix version 4.9.15 Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.

Affected Software

8 affected components
Atlassian Bitbucket Data Center>=4.6.0, <9.4.26, <10.2.8, <10.5.1
Atlassian Confluence Data Center>=5.10.0, <9.2.26, <10.2.19
Atlassian Crowd Data Center>=2.11.0, <6.3.7, <7.0.3, <7.1.1, <7.2.4
Atlassian Jira Software Data Center>=7.1.0, <9.12.40, <10.3.26, <11.3.12
Atlassian Jira Service Management Data Center>=3.1.0, <5.12.40, <10.3.26, <11.3.12
Atlassian Bamboo Data Center>=7.0.1, <10.2.24, <12.1.12
Atlassian Crucible<4.9.15
Atlassian Fisheye<4.9.15

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Bamboo Data Center to a version that resolves this vulnerability.

    Fixed in 10.2.24
  2. Upgrade

    Upgrade Bamboo Data Center to a version that resolves this vulnerability.

    Fixed in 12.1.12
  3. Upgrade

    Upgrade Bitbucket Data Center to a version that resolves this vulnerability.

    Fixed in 9.4.26
  4. Upgrade

    Upgrade Bitbucket Data Center to a version that resolves this vulnerability.

    Fixed in 10.2.8
  5. Upgrade

    Upgrade Bitbucket Data Center to a version that resolves this vulnerability.

    Fixed in 10.5.1
  6. Upgrade

    Upgrade Confluence Data Center to a version that resolves this vulnerability.

    Fixed in 9.2.26
  7. Upgrade

    Upgrade Confluence Data Center to a version that resolves this vulnerability.

    Fixed in 10.2.19
  8. Upgrade

    Upgrade Crowd Data Center to a version that resolves this vulnerability.

    Fixed in 6.3.7
  9. Upgrade

    Upgrade Crowd Data Center to a version that resolves this vulnerability.

    Fixed in 7.0.3
  10. Upgrade

    Upgrade Crowd Data Center to a version that resolves this vulnerability.

    Fixed in 7.1.1
  11. Upgrade

    Upgrade Crowd Data Center to a version that resolves this vulnerability.

    Fixed in 7.2.4
  12. Upgrade

    Upgrade Crucible to a version that resolves this vulnerability.

    Fixed in 4.9.15
  13. Upgrade

    Upgrade Fisheye to a version that resolves this vulnerability.

    Fixed in 4.9.15
  14. Upgrade

    Upgrade Jira Service Management Data Center to a version that resolves this vulnerability.

    Fixed in 5.12.40
  15. Upgrade

    Upgrade Jira Service Management Data Center to a version that resolves this vulnerability.

    Fixed in 10.3.26
  16. Upgrade

    Upgrade Jira Service Management Data Center to a version that resolves this vulnerability.

    Fixed in 11.3.12
  17. Upgrade

    Upgrade Jira Software Data Center to a version that resolves this vulnerability.

    Fixed in 9.12.40
  18. Upgrade

    Upgrade Jira Software Data Center to a version that resolves this vulnerability.

    Fixed in 10.3.26
  19. Upgrade

    Upgrade Jira Software Data Center to a version that resolves this vulnerability.

    Fixed in 11.3.12

Event History

Oct 5, 2026
CVE Published
via MITRE·09:30 PM
Data Sourced
via MITRE·09:30 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverity

Frequently Asked Questions

1

Which documented releases should be used to remediate affected Bitbucket, Confluence, and Crowd deployments?

Bitbucket Data Center is fixed in 9.4.26, 10.2.8, and 10.5.1. Confluence Data Center is fixed in 9.2.26 and 10.2.19. Crowd Data Center is fixed in 6.3.7, 7.0.3, 7.1.1, and 7.2.4.

2

How far back does the documented exposure extend for these products?

The issue was introduced in Bitbucket Data Center 4.6.0 or later, Confluence Data Center 5.10.0 or later, Crowd Data Center 2.11.0 or later, and Jira Software Data Center 7.1.0 or later. The supplied information does not provide the corresponding introduction versions for the other listed products.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203