Critical Atlassian Data Center Arbitrary File Access
π‘οΈ Atlassian has disclosed a critical arbitrary file access vulnerability (CVE-2026-21589, CVSS 9.3) affecting multiple Data Center products including Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye. The flaw allows unauthenticated attackers to retrieve specific files from the web application root if they know the exact path and filename. Atlassian released patches for impacted versions and recommends temporary mitigations such as removing instances from the public internet, deploying WAF rules, and applying Tomcat or urlrewrite.xml protections. Telemetry shows early exploitation attempts from a few IPs, and security researchers warn rapid scanning and mass exploitation are likely following public technical details.
