Skip to content
ittechwire

Technology news, clearly sourced

  1. Home
  2. Security

Security

Atlassian patches critical file-access flaw in Jira, Confluence and other Data Center products

CVE-2026-21589 lets an unauthenticated attacker read specific files from the web root of self-hosted Atlassian products. Fixed versions are out, cloud customers are already covered, and Atlassian says it has no evidence of exploitation so far.

ittechwire Editorial3 min readSources: 3

Key points

  1. 1CVE-2026-21589 allows unauthenticated access to specific files in the web root of self-hosted Atlassian products; The Register reports a rating of 9.3.
  2. 2Exploitation requires the exact file name and path; directory contents cannot be listed.
  3. 3Affected: Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible and Fisheye; fixed releases are available.
  4. 4If patching must wait, Atlassian advises restricting external access and applying WAF, proxy or rewrite-rule mitigations on every node.
  5. 5Atlassian says it has no evidence of exploitation so far; cloud customers need no action.

Full story

Atlassian has told customers of its self-hosted Data Center products to install security updates for a critical vulnerability tracked as CVE-2026-21589. According to The Register, the company emailed users on Monday with a message headed "Action required" that links to its security bulletin. The Register reports that the flaw carries a severity rating of 9.3.

The bug is an arbitrary file access weakness. Atlassian's advisory, as quoted by both outlets, says an attacker who is not logged in can reach specific files inside the web application root directory of affected versions. There is a limit: the attacker has to know the precise name and path of the file in advance, and the flaw cannot be used to list what a directory contains. Atlassian also warns that some configurations may hold sensitive files, which raises the risk.

The affected products are Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd in their Data Center editions, plus Crucible and Fisheye. BleepingComputer lists the releases that fix the problem; every earlier version is vulnerable. They are Bitbucket 9.4.26, 10.2.8 and 10.5.1; Confluence 9.2.26 and 10.2.19; Jira Service Management 5.12.40, 10.3.26 and 11.3.12; Jira Software 9.12.40, 10.3.26 and 11.3.12; Bamboo 10.2.24 and 12.1.12; Crowd 6.3.7, 7.0.3, 7.1.7 and 7.2.4; and Crucible and Fisheye 4.9.15.

Administrators who cannot upgrade immediately are advised to block outside network access, even for internet-facing instances that ask users to sign in. According to BleepingComputer, the advisory also lists temporary mitigations: a web application firewall (WAF) or proxy rule that blocks the traversal patterns named in the bulletin, Tomcat RewriteValve rules for Confluence, Jira, Jira Service Management, Bamboo and Crowd, and a URL rewrite rule for Bitbucket. Each of these changes must be applied on all cluster nodes, mirrors and mirror farm nodes of Bitbucket included.

Atlassian says it currently has no evidence that the flaw is being exploited. It still asks administrators to check their access logs for the traversal patterns it describes, and says it cannot tell whether a given customer instance has been compromised, so self-hosted customers should involve their own security team. Customers on Atlassian's cloud need to do nothing, because the company has already patched its hosted service.

Why it matters

Jira, Confluence and Bitbucket often hold internal plans, documentation and source code, and many organisations run them on their own servers. The flaw needs no login, so an instance reachable from the internet is exposed until it is updated or shielded. Atlassian itself says it cannot judge whether individual instances were affected, which leaves the log review to each customer. The Register also notes that Atlassian stopped developing its low-end server products in 2020 and later decided to discontinue its Data Center software as well, so customers still running these products have to plan both this patch and a longer-term move.

Timeline

  1. · Published

Topics#Atlassian#Jira#Confluence#Vulnerability#CVE-2026-21589#Data Center

Sources

This story draws on the following sources. Read them for full context.

  1. 1NIST National Vulnerability Database · Primary sourceCVE-2026-21589 detailnvd.nist.gov
  2. 2BleepingComputer · News reportAtlassian warns of critical file-access flaw in Jira, Confluencewww.bleepingcomputer.com
  3. 3The Register · News reportAtlassian warns of critical file access flaw in its datacenter productswww.theregister.com