{"item": {"cve_id": "CVE-2026-21589", "ghsa_id": "", "osv_id": "", "title": "CVE-2026-21589", "description": "This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.", "published_at": "2026-10-05T22:16:58.423", "modified_at": "2026-10-07T13:17:22.273", "vendor": "Atlassian", "product": "Bamboo Data Center", "affected_versions": ["All other versions"], "fixed_versions": [], "cvss_score": 9.3, "cvss_version": "4.0", "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "severity": "CRITICAL", "epss_score": 0.01773, "epss_percentile": 0.77527, "epss_date": "2026-10-09", "is_kev": false, "kev_date": "", "kev_due_date": "", "kev_action": "", "cwe_ids": ["CWE-552"], "attack_vector": "", "attack_complexity": "", "privileges_required": "", "user_interaction": "", "references": ["https://jira.atlassian.com/browse/BAM-26567", "https://jira.atlassian.com/browse/BSERV-20604", "https://jira.atlassian.com/browse/CONFSERVER-104488", "https://jira.atlassian.com/browse/CRUC-8741", "https://jira.atlassian.com/browse/CWD-6610", "https://jira.atlassian.com/browse/FE-7583", "https://jira.atlassian.com/browse/JRASERVER-79546", "https://jira.atlassian.com/browse/JSDSERVER-16809", "https://github.com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589"], "source_urls": {"NVD": "https://nvd.nist.gov/vuln/detail/CVE-2026-21589", "CVE.org": "https://www.cve.org/CVERecord?id=CVE-2026-21589", "FIRST EPSS": "https://api.first.org/data/v1/epss?cve=CVE-2026-21589"}, "patch_available": null, "workaround_available": null, "sources": ["NVD", "CVE.org", "FIRST EPSS"], "reference_items": [{"url": "https://jira.atlassian.com/browse/BAM-26567", "tags": [], "source": "NVD", "name": ""}, {"url": "https://jira.atlassian.com/browse/BSERV-20604", "tags": [], "source": "NVD", "name": ""}, {"url": "https://jira.atlassian.com/browse/CONFSERVER-104488", "tags": [], "source": "NVD", "name": ""}, {"url": "https://jira.atlassian.com/browse/CRUC-8741", "tags": [], "source": "NVD", "name": ""}, {"url": "https://jira.atlassian.com/browse/CWD-6610", "tags": [], "source": "NVD", "name": ""}, {"url": "https://jira.atlassian.com/browse/FE-7583", "tags": [], "source": "NVD", "name": ""}, {"url": "https://jira.atlassian.com/browse/JRASERVER-79546", "tags": [], "source": "NVD", "name": ""}, {"url": "https://jira.atlassian.com/browse/JSDSERVER-16809", "tags": [], "source": "NVD", "name": ""}, {"url": "https://github.com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589", "tags": ["exploit"], "source": "NVD", "name": ""}], "cvss_v4_score": 9.3, "cvss_v4_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "cvss_v4_severity": "CRITICAL", "nvd_status": "Awaiting Analysis", "cna": "atlassian", "date_reserved": "2026-01-01T00:00:40.722Z", "ssvc": {"options": {"Exploitation": "poc", "Automatable": "no", "Technical Impact": "total"}, "version": "2.0.3", "timestamp": "2026-10-07T13:04:54.917548Z", "role": "CISA Coordinator"}, "affected_products": [{"vendor": "Atlassian", "product": "Bamboo Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 10.2.24 and later", "Patch version 12.1.12 and later"], "source": "CVE.org"}, {"vendor": "Atlassian", "product": "Bitbucket Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 10.2.8 and later", "Patch version 10.5.1 and later", "Patch version 9.4.26 and later"], "source": "CVE.org"}, {"vendor": "Atlassian", "product": "Confluence Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 10.2.19 and later", "Patch version 9.2.26 and later"], "source": "CVE.org"}, {"vendor": "Atlassian", "product": "Crowd Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 7.2.4 and later", "Patch version 7.1.7 and later", "Patch version 7.0.3 and later", "Patch version 6.3.7 and later"], "source": "CVE.org"}, {"vendor": "Atlassian", "product": "Crucible Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 4.9.15 and later"], "source": "CVE.org"}, {"vendor": "Atlassian", "product": "Fisheye Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 4.9.15 and later"], "source": "CVE.org"}, {"vendor": "Atlassian", "product": "Jira Service Management Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 11.3.12 and later", "Patch version 10.3.26 and later", "Patch version 5.12.40 and later"], "source": "CVE.org"}, {"vendor": "Atlassian", "product": "Jira Software Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 11.3.12 and later", "Patch version 10.3.26 and later", "Patch version 9.12.40 and later"], "source": "CVE.org"}], "kev_name": "", "kev_short_description": "", "kev_ransomware": "", "kev_notes": "", "kev_cwes": [], "wordfence_id": "", "mentions_sources": [], "version_match": "unknown", "risk_score": 45, "risk_class": "Modéré", "impact": {"summary": "D'après les sources, l'impact direct sur la confidentialité, l'intégrité ou la disponibilité est limité ou non renseigné.", "basis": "CVSS 4.0"}, "mechanism": "Manipulation de fichiers arbitraires sur le système.", "mitigation": {"correction": {"available": true, "text": "Mettre à jour : selon les sources, ne sont plus concernées les versions à partir de Bamboo Data Center Patch version 10.2.24 and later, Bamboo Data Center Patch version 12.1.12 and later, Bitbucket Data Center Patch version 10.2.8 and later, Bitbucket Data Center Patch version 10.5.1 and later, Bitbucket Data Center Patch version 9.4.26 and later."}, "mitigation": {"specific": "Aucune mesure de mitigation spécifique confirmée par les sources consultées. Consultez les références officielles pour d'éventuelles mesures détaillées.", "general": ["Maintenir le produit à jour et activer les mises à jour de sécurité.", "Restreindre l'exposition réseau du service au strict nécessaire.", "Appliquer le principe du moindre privilège.", "Surveiller les journaux et les alertes de sécurité."], "specific_links": []}, "containment": {"applicable": false, "actions": []}, "note": "Priorité aux consignes officielles de l'éditeur et des références. Vérifiez toujours l'avis de sécurité avant toute intervention en production.", "official_links": []}, "plain": {"verdict": "watch", "verdict_label": "À surveiller · pas d'urgence immédiate", "verdict_css": "watch", "verdict_rank": 2, "headline": "Faille de sécurité signalée dans Bamboo Data Center", "headline_is_derived": false, "action": "Mettre à jour vers Bamboo Data Center Patch version 10.2.24 and later, Bamboo Data Center Patch version 12.1.12 and later, Bitbucket Data Center Patch version 10.2.8 and later, Bitbucket Data Center Patch version 10.5.1 and later ou plus récent, version publiée comme non concernée.", "action_kind": "update", "concerned": [{"version": "Bamboo Data Center Patch version 10.2.24 and later, Bamboo Data Center Patch version 12.1.12 and later, Bitbucket Data Center Patch version 10.2.8 and later, Bitbucket Data Center Patch version 10.5.1 and later ou plus récent", "state": "safe", "state_label": "Non concerné", "todo": "Rien à faire. Gardez les mises à jour automatiques activées."}, {"version": "All other versions", "state": "hit", "state_label": "Concerné", "todo": "Mettre à jour vers Bamboo Data Center Patch version 10.2.24 and later, Bamboo Data Center Patch version 12.1.12 and later, Bitbucket Data Center Patch version 10.2.8 and later, Bitbucket Data Center Patch version 10.5.1 and later ou plus récent, version publiée comme non concernée."}, {"version": "Je ne connais pas ma version", "state": "unknown", "state_label": "À vérifier", "todo": "La version s'affiche généralement dans le menu « À propos » ou « Aide » du logiciel."}], "steps": [{"title": "Sauvegarder avant d'intervenir", "detail": "Une copie récente des données et de la configuration. Si votre hébergeur propose une sauvegarde en un clic, c'est le moment.", "duration": "10 min", "priority": false}, {"title": "Mettre à jour vers Bamboo Data Center Patch version 10.2.24 and later, Bamboo Data Center Patch version 12.1.12 and later, Bitbucket Data Center Patch version 10.2.8 and later, Bitbucket Data Center Patch version 10.5.1 and later ou plus récent, version publiée comme non concernée", "detail": "C'est la correction officielle. Tant qu'elle n'est pas appliquée, les autres mesures ne sont que temporaires.", "duration": "15 à 45 min", "priority": true}, {"title": "Confirmer que tout fonctionne encore", "detail": "Après correction : page d'accueil, connexion, et les deux ou trois fonctions dont vous vous servez tous les jours.", "duration": "10 min", "priority": false}], "exploited": false, "exploited_label": "Pas à ce jour", "fixed_label": "Bamboo Data Center Patch version 10.2.24 and later, Bamboo Data Center Patch version 12.1.12 and later, Bitbucket Data Center Patch version 10.2.8 and later, Bitbucket Data Center Patch version 10.5.1 and later (non concernée selon les sources)", "affected_label": "All other versions"}, "severity_display": "Critique", "cvss_is_legacy": false, "risk_score_computable": true, "identifier": "CVE-2026-21589", "severity_fr": "Critique", "epss_pct": 1.8, "source_records": [{"source": "NVD", "label": "NVD, NIST", "date_label": "Publié dans la base", "date": "2026-10-05", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21589"}, {"source": "CVE.org", "label": "CVE.org, programme CVE", "date_label": "Publié par l'organisme CNA", "date": "2026-10-05", "url": "https://www.cve.org/CVERecord?id=CVE-2026-21589"}, {"source": "FIRST EPSS", "label": "FIRST EPSS", "date_label": "Score daté du", "date": "2026-10-09", "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-21589"}], "exploit_public": true, "reseau_sans_auth": true, "exposition": "À distance, sans compte et sans action d'un utilisateur", "owasp": [{"code": "A01", "nom": "Contrôle d'accès défaillant", "nom_officiel": "Broken Access Control", "slug": "a01-controle-d-acces-defaillant", "libelle": "A01:2025 Contrôle d'accès défaillant", "url_officielle": "https://top10.owasp.org/2025/A01_2025-Broken_Access_Control/"}]}, "presentation": {"en_bref": [{"question": "Est-elle attaquée ?", "ton": "vigilance", "reponse": "Pas d'attaque confirmée, mais un code d'exploitation public existe", "source": "1 référence(s) étiquetée(s) « exploit »"}, {"question": "Existe-t-il un correctif ?", "ton": "bon", "reponse": "Oui : Patch version 10.2.24 and later, Patch version 12.1.12 and later, Patch version 10.2.8 and later, Patch version 10.5.1 and later…", "source": "Versions publiées comme non concernées"}, {"question": "Comment l'attaquer ?", "ton": "alerte", "reponse": "À distance, sans compte et sans action d'un utilisateur", "source": "Vecteur CVSS publié"}, {"question": "Risque d'exploitation", "ton": "vigilance", "reponse": "1,8 % sur 30 jours", "source": "Plus probable que 78 % des failles connues"}], "references": [{"cle": "exploit", "titre": "Codes d'exploitation référencés", "explication": "Les sources signalent un code d'exploitation public. Par prudence, CyberAlert affiche le site qui l'héberge sans lien direct : l'information utile ici est son existence, qui rend la faille plus facile à attaquer.", "items": [{"url": "https://github.com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589", "domaine": "github.com", "editeur": "GitHub", "etiquettes": ["Code d'exploitation"], "nom": "", "lien": false, "casse": false}]}, {"cle": "autres", "titre": "Autres références", "explication": "Références publiées sans étiquette par les sources : leur nature n'est pas qualifiée.", "items": [{"url": "https://jira.atlassian.com/browse/BAM-26567", "domaine": "jira.atlassian.com", "editeur": "", "etiquettes": [], "nom": "", "lien": true, "casse": false}, {"url": "https://jira.atlassian.com/browse/BSERV-20604", "domaine": "jira.atlassian.com", "editeur": "", "etiquettes": [], "nom": "", "lien": true, "casse": false}, {"url": "https://jira.atlassian.com/browse/CONFSERVER-104488", "domaine": "jira.atlassian.com", "editeur": "", "etiquettes": [], "nom": "", "lien": true, "casse": false}, {"url": "https://jira.atlassian.com/browse/CRUC-8741", "domaine": "jira.atlassian.com", "editeur": "", "etiquettes": [], "nom": "", "lien": true, "casse": false}, {"url": "https://jira.atlassian.com/browse/CWD-6610", "domaine": "jira.atlassian.com", "editeur": "", "etiquettes": [], "nom": "", "lien": true, "casse": false}, {"url": "https://jira.atlassian.com/browse/FE-7583", "domaine": "jira.atlassian.com", "editeur": "", "etiquettes": [], "nom": "", "lien": true, "casse": false}, {"url": "https://jira.atlassian.com/browse/JRASERVER-79546", "domaine": "jira.atlassian.com", "editeur": "", "etiquettes": [], "nom": "", "lien": true, "casse": false}, {"url": "https://jira.atlassian.com/browse/JSDSERVER-16809", "domaine": "jira.atlassian.com", "editeur": "", "etiquettes": [], "nom": "", "lien": true, "casse": false}]}], "liens_correction": [], "nb_exploits": 1, "cvss": null, "cvss4": {"version": "4.0", "vecteur": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "metriques": [{"code": "AV", "nom": "Vecteur d'attaque", "valeur": "Réseau (à distance, y compris par Internet)", "brut": "N", "explication": "D'où l'attaquant doit agir."}, {"code": "AC", "nom": "Complexité de l'attaque", "valeur": "Faible", "brut": "L", "explication": "Conditions hors du contrôle de l'attaquant."}, {"code": "AT", "nom": "Conditions d'attaque", "valeur": "Aucune", "brut": "N", "explication": "Conditions de déploiement nécessaires à l'attaque."}, {"code": "PR", "nom": "Privilèges requis", "valeur": "Aucun (pas de compte)", "brut": "N", "explication": "Droits dont l'attaquant a besoin avant d'attaquer."}, {"code": "UI", "nom": "Interaction de l'utilisateur", "valeur": "Aucune", "brut": "N", "explication": "Une victime doit-elle agir ?"}, {"code": "VC", "nom": "Confidentialité du système vulnérable", "valeur": "Élevé", "brut": "H", "explication": ""}, {"code": "VI", "nom": "Intégrité du système vulnérable", "valeur": "Aucun", "brut": "N", "explication": ""}, {"code": "VA", "nom": "Disponibilité du système vulnérable", "valeur": "Aucun", "brut": "N", "explication": ""}, {"code": "SC", "nom": "Confidentialité des systèmes suivants", "valeur": "Élevé", "brut": "H", "explication": "Systèmes touchés par rebond."}, {"code": "SI", "nom": "Intégrité des systèmes suivants", "valeur": "Élevé", "brut": "H", "explication": "Systèmes touchés par rebond."}, {"code": "SA", "nom": "Disponibilité des systèmes suivants", "valeur": "Élevé", "brut": "H", "explication": "Systèmes touchés par rebond."}], "calculateur": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "specification": "https://www.first.org/cvss/v4.0/specification-document"}, "cwe": [{"id": "CWE-552", "nom": "", "url": "https://cwe.mitre.org/data/definitions/552.html"}], "owasp": [{"code": "A01", "nom": "Contrôle d'accès défaillant", "nom_officiel": "Broken Access Control", "slug": "a01-controle-d-acces-defaillant", "libelle": "A01:2025 Contrôle d'accès défaillant", "url_officielle": "https://top10.owasp.org/2025/A01_2025-Broken_Access_Control/"}], "ssvc": {"lignes": [{"nom": "Exploitation", "valeur": "Une preuve de concept publique existe", "brut": "poc"}, {"nom": "Automatisable", "valeur": "Non : l'attaque ne peut pas être entièrement automatisée", "brut": "no"}, {"nom": "Impact technique", "valeur": "Total : contrôle complet du composant ou de ses informations", "brut": "total"}], "version": "2.0.3", "date": "2026-10-07", "role": "CISA Coordinator", "url": "https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc"}, "chronologie": [{"date": "2026-01-01", "libelle": "Identifiant réservé", "qui": "Programme CVE"}, {"date": "2026-10-05", "libelle": "Publication de la vulnérabilité", "qui": "atlassian"}, {"date": "2026-10-07", "libelle": "Dernière mise à jour de la fiche source", "qui": "Source"}, {"date": "2026-10-07", "libelle": "Décision SSVC publiée", "qui": "CISA"}, {"date": "2026-10-09", "libelle": "Calcul du score EPSS affiché", "qui": "FIRST"}], "liens_officiels": [{"nom": "NVD (NIST)", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21589", "description": "Fiche de référence : CVSS, CPE, références étiquetées."}, {"nom": "CVE.org", "url": "https://www.cve.org/CVERecord?id=CVE-2026-21589", "description": "Enregistrement officiel publié par l'organisme qui a attribué l'identifiant."}, {"nom": "FIRST EPSS", "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-21589", "description": "Score de probabilité d'exploitation du jour."}, {"nom": "OSV.dev", "url": "https://osv.dev/vulnerability/CVE-2026-21589", "description": "Paquets open source concernés et versions corrigées."}, {"nom": "GitHub Advisory Database", "url": "https://github.com/advisories?query=CVE-2026-21589", "description": "Avis de sécurité des dépendances logicielles."}], "produits": [{"vendor": "Atlassian", "product": "Bamboo Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 10.2.24 and later", "Patch version 12.1.12 and later"], "source": "CVE.org"}, {"vendor": "Atlassian", "product": "Bitbucket Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 10.2.8 and later", "Patch version 10.5.1 and later", "Patch version 9.4.26 and later"], "source": "CVE.org"}, {"vendor": "Atlassian", "product": "Confluence Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 10.2.19 and later", "Patch version 9.2.26 and later"], "source": "CVE.org"}, {"vendor": "Atlassian", "product": "Crowd Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 7.2.4 and later", "Patch version 7.1.7 and later", "Patch version 7.0.3 and later", "Patch version 6.3.7 and later"], "source": "CVE.org"}, {"vendor": "Atlassian", "product": "Crucible Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 4.9.15 and later"], "source": "CVE.org"}, {"vendor": "Atlassian", "product": "Fisheye Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 4.9.15 and later"], "source": "CVE.org"}, {"vendor": "Atlassian", "product": "Jira Service Management Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 11.3.12 and later", "Patch version 10.3.26 and later", "Patch version 5.12.40 and later"], "source": "CVE.org"}, {"vendor": "Atlassian", "product": "Jira Software Data Center", "ranges": ["All other versions"], "first_unaffected": ["Patch version 11.3.12 and later", "Patch version 10.3.26 and later", "Patch version 9.12.40 and later"], "source": "CVE.org"}], "notes_kev": []}, "consulted_at": "2026-10-09T23:22:58.493312+00:00"}