← Back to the live CVE advisory feed

CVE-2026-21589: Bamboo Data Center

Severity
9.3 (CRITICAL)
Vendor
ATLASSIAN
Affected versions
All other versions; All versions
Fixed version
Patch version 10.2.4 and later
Patch status
Patched
Published
2026-10-05T22:16:58.423
Modified
2026-10-05T22:16:58.423

Why it matters

This matters because the affected product may be exploitable without valid credentials. Internet-facing deployments should be reviewed first.

Recommended admin actions

  • Prioritize validation immediately due to critical CVSS severity.
  • Treat internet-facing systems as higher priority.

Technical summary

h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe.   h3. Context This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. h3. Details: * The vulnerability must be addressed for affected versions of: Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.1, 7.2.4 Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 Crucible, fix versions 4.9.15 Fisheye, fix version 4.9.15 * Exploitation requires prior knowledge of the target file's exact name and path. * The vulnerability does not include the capability to enumerate or list directory contents.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: OCT 06, 2026 12:00 AM UTC
406 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-100103
Product identification pending PATCH
Reporter: SECURITY
10
CRITICAL
VIEW RECORD
CVE-2026-105636
plane PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-105691
penpot PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-105697
langflow PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-105740
langflow PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-88395
Product identification pending
Reporter: CVE
9.8
CRITICAL
VIEW RECORD
CVE-2026-105639
plane PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-105641
plane PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-97283
Advanced Post Manager PATCH
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-105637
plane PATCH
Reporter: SECURITY-ADVISORIES
9.6
CRITICAL
VIEW RECORD
CVE-2026-100102
Product identification pending PATCH
Reporter: SECURITY
9.5
CRITICAL
VIEW RECORD
CVE-2026-103510
Product identification pending PATCH
Reporter: SECURITY
9.5
CRITICAL
VIEW RECORD
CVE-2026-105284
A3002MU
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-105285
A3002MU
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-102428
OrdaSoft Joomla CCK
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-103352
WP BASE Booking PATCH
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-21589
Bamboo Data Center PATCH
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-91107
openSIS-Classic
Reporter: HELP
9.3
CRITICAL
VIEW RECORD
CVE-2026-105293
Product identification pending
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-77226
Product identification pending PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-105223
Product identification pending PATCH
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-105294
Product identification pending
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-105638
plane PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-105640
plane PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-79820
HPE Integrated Lights-Out (iLO) 7
Reporter: SECURITY-ALERT
9
CRITICAL
VIEW RECORD
CVE-2026-20586
Product identification pending
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92931
Product identification pending
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-101919
Product identification pending
Reporter: SECALERT
8.8
HIGH
VIEW RECORD
CVE-2026-105642
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-45524
Product identification pending
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-55280
Product identification pending
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-58835
Product identification pending
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-100511
Product identification pending
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-97257
Product identification pending
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-102775
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-104892
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-104966
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-104968
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-104976
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-104979
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-105630
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-105632
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-104389
Product identification pending
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-104805
Mitel MiVoice Office 400
Reporter: VULNERABILITY
8.5
HIGH
VIEW RECORD
CVE-2026-63277
Product identification pending
Reporter: SECURITY
8.5
HIGH
VIEW RECORD
CVE-2026-104971
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.5
HIGH
VIEW RECORD
CVE-2026-103066
Product identification pending
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-20521
Product identification pending
Reporter: SECURITY
8.4
HIGH
VIEW RECORD
CVE-2026-20522
Product identification pending
Reporter: SECURITY
8.4
HIGH
VIEW RECORD
CVE-2026-20523
Product identification pending
Reporter: SECURITY
8.4
HIGH
VIEW RECORD
CVE-2026-20524
Product identification pending
Reporter: SECURITY
8.4
HIGH
VIEW RECORD
CVE-2026-20531
Product identification pending
Reporter: SECURITY
8.4
HIGH
VIEW RECORD
CVE-2026-104706
Mitel MiVoice Office 400
Reporter: VULNERABILITY
8.4
HIGH
VIEW RECORD
CVE-2026-104809
Mitel MiVoice Office 400
Reporter: VULNERABILITY
8.4
HIGH
VIEW RECORD
CVE-2026-104810
Mitel MiVoice Office 400
Reporter: VULNERABILITY
8.4
HIGH
VIEW RECORD
CVE-2026-104811
Mitel MiVoice Office 400
Reporter: VULNERABILITY
8.4
HIGH
VIEW RECORD
CVE-2026-19184
Product identification pending
Reporter: VULNERABILITIES
8.4
HIGH
VIEW RECORD
CVE-2026-12171
Product identification pending PATCH
Reporter: 7FFCEE3D-2C14-4C3E-B844-86C6A321A158
8.4
HIGH
VIEW RECORD
CVE-2026-86671
Product identification pending
Reporter: EMO
8.4
HIGH
VIEW RECORD
CVE-2026-104978
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-94201
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
8.2
HIGH
VIEW RECORD
CVE-2026-104852
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-104970
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-104974
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-105634
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-105650
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-77805
Product identification pending
Reporter: SECURITY
7.9
HIGH
VIEW RECORD
CVE-2026-19185
Product identification pending
Reporter: VULNERABILITIES
7.8
HIGH
VIEW RECORD
CVE-2026-49885
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-49933
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-49937
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-55266
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-55269
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-55270
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-55286
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-58815
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-58841
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-58854
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-58859
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-105295
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-104977
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-104408
Product identification pending
Reporter: AUDIT
7.6
HIGH
VIEW RECORD
CVE-2026-104973
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-105628
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-97303
Product identification pending
Reporter: AUDIT
7.6
HIGH
VIEW RECORD
CVE-2026-20519
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-20520
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-20526
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-105314
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-103507
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-104891
mppx-condition-gate PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-105631
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-93318
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-103334
Product identification pending
Reporter: AUDIT
7.5
HIGH
VIEW RECORD
CVE-2026-58865
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-105675
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-0461
Product identification pending
Reporter: PSIRT
7.5
HIGH
VIEW RECORD
CVE-2026-105744
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-105635
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.4
HIGH
VIEW RECORD
CVE-2026-105643
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.3
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.