Atlassian patches critical file access flaw hitting every Data Center version of eight products
Atlassian says CVE-2026-21589 lets unauthenticated attackers read files from the web application root of Jira, Confluence, Bitbucket and five other self-hosted products. All versions are affected.
At a glance
- Atlassian rates CVE-2026-21589 critical at CVSS 9.3; no authentication is required to read files from the web application root directory.
- All versions of Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye Data Center are affected.
- Atlassian Cloud instances are already patched and the company says it found no evidence of exploitation there.
- Admins who cannot patch now are told to pull affected instances off the public internet.
Atlassian disclosed a critical file access vulnerability on 5 October 2026 that, according to the company's own advisory, affects every version of eight self-hosted enterprise products, including Jira, Confluence, Bitbucket and Bamboo. Tracked as CVE-2026-21589, the flaw lets an unauthenticated attacker read specific files from the web application root directory. Atlassian rated it critical with a CVSS 4.0 base score of 9.3 and told administrators to patch without delay.
What happened
According to Atlassian's advisory, the vulnerability sits in the Data Center products that organisations run on their own infrastructure: Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. The company states that all versions of these products are vulnerable, which means there is no release that customers can treat as safe without updating.
Atlassian said its Cloud products have already been patched, that its investigation found no evidence of exploitation against Cloud, and that Cloud customers need to take no action. The advisory does not report confirmed exploitation of self-managed instances either, and no exploitation claim has been attributed to a threat actor at the time of writing.
Technical details
The advisory describes the issue as arbitrary file access and publishes the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H — network reachable, low attack complexity, no privileges and no user interaction required. Atlassian notes an important limit: an attacker has to know the exact name and path of the file they want, because the flaw does not allow directory enumeration or listing of directory contents. That narrows blind exploitation, but it does not help organisations whose deployments sit at predictable paths. Atlassian warned that "in some configurations, there may be sensitive files present that increase your risk."
Who is affected
The affected list covers issue tracking, documentation, source code hosting, build automation and identity directory services, so a single unpatched host can expose very different classes of data depending on the product. The Register reported on 6 October that instances reachable from the public internet face elevated risk, and that the disclosure lands while Atlassian keeps pushing customers from Data Center towards Cloud. Daily CyberSecurity also covered the advisory on 6 October, describing the impact as spanning Jira, Confluence, Bitbucket and five further products.
What to do
Atlassian lists these fixed releases: Bitbucket 9.4.26, 10.2.8 and 10.5.1; Confluence 9.2.26 and 10.2.19; Jira Service Management 5.12.40, 10.3.26 and 11.3.12; Jira Software 9.12.40, 10.3.26 and 11.3.12; Bamboo 10.2.24 and 12.1.12; Crowd 6.3.7, 7.0.3, 7.1.7 and 7.2.4; Crucible and Fisheye 4.9.15.
Where immediate patching is not possible, Atlassian's guidance is to restrict the instance from external network access until it can be updated. The advisory also points to interim options: web application firewall rules that block path traversal patterns, a Tomcat RewriteValve configuration for most of the products, and a urlrewrite.xml change for Bitbucket. Teams that run any of these services on the internet should treat patching as urgent and review what files sit in the application root.
Related CVEs
Sources
- CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products — Atlassian
- Atlassian warns of critical file access flaw in its datacenter products — The Register
- Critical Atlassian Flaw CVE-2026-21589 Exposes Files in Jira, Confluence, Bitbucket and Five More Products — Daily CyberSecurity (securityonline.info)
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



