VORANT. Threat Intelligence Research Sign in Create a free account

Atlassian Data Center flaw exposes files unauthenticated

routine vulnerability

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

An unauthenticated arbitrary file access flaw (CVE-2026-21589, CVSS 9.3) affects multiple Atlassian Data Center products; patches are available.

NCSC-NL published an advisory describing a file disclosure vulnerability affecting Atlassian's Data Center product line, including Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible and Fisheye. The flaw, tracked as CVE-2026-21589 and rated CVSS v4 9.3, allows unauthenticated attackers to access specific files within the web application's root directory, provided they know the exact file path and name. This could expose sensitive files and configuration data, posing a confidentiality risk to affected deployments.

Atlassian has released patched versions for the affected products. The advisory does not indicate evidence of active exploitation in the wild, but given the breadth of affected products and the high CVSS score, organizations running any of the listed Atlassian Data Center products should prioritize applying the vendor patches. Defenders should inventory Data Center deployments across all listed product families and verify patch status, as exploitation requires no authentication and only knowledge of file paths, which could be enumerated or guessed in some configurations.

Mentioned in this report

Vulnerabilities CVE-2026-21589

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0402.html

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,850 reports from 149 sources, 467 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs