Atlassian disclosed CVE-2026-21589 on October 5 — a path traversal rated 9.3 out of 10 under CVSS 4.0 that can be exploited remotely without any login across eight self-hosted Data Center products. An attacker can read specific files inside the web application root directory, provided they already know a file's exact name and path; they cannot list the directory's contents. Atlassian notes that in some configurations that directory holds sensitive files, which raises the risk.
The affected products are Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. Atlassian lists fixed versions for each, including Confluence 9.2.26 and 10.2.19, Jira Software 9.12.40, 10.3.26 and 11.3.12, and Bitbucket 9.4.26, 10.2.8 and 10.5.1. All earlier versions are considered vulnerable, potentially including end-of-life releases. Atlassian's cloud products have already been patched and cloud customers need take no action; Bitbucket Cloud is not affected.
Customers who cannot upgrade everything at once should, if possible, take the instance offline. Any instance reachable from the public internet — including one that requires a login — should be blocked from outside access until it is upgraded or a temporary blocking rule is in place. Atlassian describes three interim mitigations: a web application firewall or reverse proxy rule for all eight products that blocks requests whose URL contains '..' immediately next to '/', '\\' or '::', including URL-encoded forms; a Tomcat RewriteValve rule installed on every node for Confluence, Jira Software, Jira Service Management, Bamboo and Crowd; and a rule in urlrewrite.xml for Bitbucket, applied to every node, mirror and mirror farm node. Each requires a restart, and Atlassian stresses the mitigations 'are limited and not a replacement for patching your instance'.
The reaction shows how seriously the flaw is being taken: attacks were observed shortly after the warning, and security vendors tracked the first exploitation attempts. Atlassian said its investigation has found no evidence of exploitation of its cloud products and states that it 'cannot confirm if your instances have been affected by this vulnerability'. Administrators are advised to have security teams search access logs — URL-decoding each request line up to twice and looking for '..' directly next to '/', '\\' or '::', or running Atlassian's block pattern over raw log lines. There is precedent: CVE-2021-26086, another Jira path traversal, was added to CISA's catalog of known exploited vulnerabilities in November 2024.
The advisory's own detail is worth reading closely. The CVE record also lists the products' older Server editions as affected — Bamboo Server, Bitbucket Server, Confluence Server and Crowd Server, in every version and with no fixed releases listed — even though the advisory does not mention them. There are also discrepancies in the fixed-version data: for Crowd, the ticket and its table cite 7.1.7 and 7.1.6 respectively, and Crowd has had no Server release since version 5.2 in September 2023.
Sources
- thehackernews.comCritical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products (The Hacker News)
- theregister.comAtlassian warns of critical file access flaw in its datacenter products (The Register)
- rapid7.comCVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products (Rapid7)
- heise.deFreitag: TSMC-Auftrag für Globalfoundries, Österreichs offene Beweisermittlung (heise online – Angriffe auf Atlassian-Data-Center-Lücke)




