Skip to main content

CVE-2026-21589: Path Traversal (Arbitrary Read/Write) in Atlassian Bamboo Data Center

0
Critical
VulnerabilityCVE-2026-21589cvecve-2026-21589
Published: 10/05/2026 (10/05/2026, 21:30:00 UTC)
Source: CVE Database V5
Vendor/Project: Atlassian
Product: Bamboo Data Center

Description

h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe.   h3. Context This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. h3. Details: * The vulnerability must be addressed for affected versions of: Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.1, 7.2.4 Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 Crucible, fix versions 4.9.15 Fisheye, fix version 4.9.15 * Exploitation requires prior knowledge of the target file's exact name and path. * The vulnerability does not include the capability to enumerate or list directory contents.

CVSS v4.0

Score 9.3critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
High
Subsq. Integrity
High
Subsq. Availability
High
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H

Affected software

Atlassian

Bamboo Data Center

Atlassian

Bamboo Server

Atlassian

Bitbucket Data Center

Atlassian

Bitbucket Server

Atlassian

Confluence Data Center

Atlassian

Confluence Server

Atlassian

Crowd Data Center

Atlassian

Crowd Server

Atlassian

Crucible Data Center

Atlassian

Crucible Server

Atlassian

Fisheye Data Center

Atlassian

Fisheye Server

Atlassian

Jira Service Management Data Center

Atlassian

Jira Service Management Server

Atlassian

Jira Software Data Center

Atlassian

Jira Software Server

Technical Details

Data Version
5.2
Assigner Short Name
atlassian
Date Reserved
2026-01-01T00:00:40.722Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ac417c92cdf04f6563c409f

Added to database: 10/05/2026, 21:34:01 UTC

Last updated: 10/05/2026, 21:34:01 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses