Answer in brief
CVE-2026-21589 records a Critical severity (CVSS 9.3) vulnerability in CISA ADP Vulnrichment. The current sources do not mark it as known exploited. The current feed maps Atlassian/Bamboo Data Center (generic), Atlassian/Bamboo Server (generic), Atlassian/Bitbucket Data Center (generic), Atlassian/Bitbucket Server (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Atlassian/Bamboo Data Center (generic), Atlassian/Bamboo Server (generic), Atlassian/Bitbucket Data Center (generic), Atlassian/Bitbucket Server (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Atlassian/Bamboo Data Centergeneric | All other versions | Not reported |
| Atlassian/Bamboo Servergeneric | All versions | Not reported |
| Atlassian/Bitbucket Data Centergeneric | All other versions | Not reported |
| Atlassian/Bitbucket Servergeneric | All versions | Not reported |
| Atlassian/Confluence Data Centergeneric | All other versions | Not reported |
| Atlassian/Confluence Servergeneric | All versions | Not reported |
| Atlassian/Crowd Data Centergeneric | All other versions | Not reported |
| Atlassian/Crowd Servergeneric | All versions | Not reported |
| Atlassian/Crucible Data Centergeneric | All other versions | Not reported |
| Atlassian/Crucible Servergeneric | All other versions | Not reported |
| Atlassian/Fisheye Data Centergeneric | All other versions | Not reported |
| Atlassian/Fisheye Servergeneric | All other versions | Not reported |
| Atlassian/Jira Service Management Data Centergeneric | All other versions | Not reported |
| Atlassian/Jira Service Management Servergeneric | All other versions | Not reported |
| Atlassian/Jira Software Data Centergeneric | All other versions | Not reported |
| Atlassian/Jira Software Servergeneric | All other versions | Not reported |
Published upstream
Oct 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 5, 2026
h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. h3. Context This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. h3. Details: * The vulnerability must be addressed for affected versions of: Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.1, 7.2.4 Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 Crucible, fix versions 4.9.15 Fisheye, fix version 4.9.15 * Exploitation requires prior knowledge of the target file's exact name and path. * The vulnerability does not include the capability to enumerate or list directory contents.
Quoted source text, attributed separately from HOL analysis.