Atlassian Warns That Eight Data Center Products Share One Critical, Unauthenticated File-Access Flaw
Atlassian rates CVE-2026-21589 a critical 9.3 and says all versions of eight Data Center products are affected. Cloud is already patched; self-hosted teams must upgrade.
Atlassian has told customers who run its software themselves to patch now. On Monday the company published an advisory for CVE-2026-21589, an arbitrary file access flaw it rates 9.3 (Critical) on the CVSS 4.0 scale. Atlassian says all versions of Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye are affected. Atlassian says the affected cloud products have already been patched, so the work falls on teams that host the software on their own infrastructure.
Table Of Content
The Register reported that the advisory reached customers as an email that opens with the words “Action required.” According to Atlassian’s advisory, the flaw “allows an unauthenticated attacker to access specific files within the web application root directory in affected versions.” Two limits apply: exploitation “requires prior knowledge of the target file’s exact name and path,” and the bug does not let an attacker list directory contents. Atlassian then adds a caution that cuts the other way: “In some configurations, there may be sensitive files present that increase your risk.”
Which versions are fixed
Atlassian lists fixed releases for each product and recommends patching to the fixed LTS version or later. The table also shows which temporary mitigations the advisory offers for each product, which are described below.
| Product | Fixed versions | Stopgaps in the advisory |
|---|---|---|
| Bitbucket Data Center | 9.4.26, 10.2.8, 10.5.1 | Firewall or proxy rule, urlrewrite.xml rule |
| Confluence Data Center | 9.2.26, 10.2.19 | Firewall or proxy rule, Tomcat RewriteValve |
| Jira Service Management Data Center | 5.12.40, 10.3.26, 11.3.12 | Firewall or proxy rule, Tomcat RewriteValve |
| Jira Software Data Center | 9.12.40, 10.3.26, 11.3.12 | Firewall or proxy rule, Tomcat RewriteValve |
| Bamboo Data Center | 10.2.24, 12.1.12 | Firewall or proxy rule, Tomcat RewriteValve |
| Crowd Data Center | 6.3.7, 7.0.3, 7.1.7, 7.2.4 | Firewall or proxy rule, Tomcat RewriteValve |
| Crucible | 4.9.15 | Firewall or proxy rule only |
| Fisheye | 4.9.15 | Firewall or proxy rule only |
The Crowd row needs a second look. The advisory gives 7.1.7 for the Crowd 7.1 line, while the description in NVD’s record of the CVE gives 7.1.1. The advisory is the primary document, so check its table before you upgrade a Crowd 7.1 instance.
The fixes arrive as maintenance releases rather than hotfix files. Under what the advisory calls a new policy, “critical security bug fixes will be back ported,” and “Binary patches are no longer released.”
How Atlassian scored it
Atlassian’s vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H. Read plainly, that describes a bug reachable over the network with no privileges, no user interaction and no special conditions. It rates the impact on the vulnerable system as high for confidentiality only, and the impact on subsequent systems as high for confidentiality, integrity and availability. Atlassian does not explain the subsequent-system values. They are consistent with its warning about sensitive files, but that is an inference, not something the advisory says.
The company also calls the number its own: “This is our assessment, and you should evaluate its applicability to your own IT environment.” NVD’s record, published October 5, has the status Received, carries only Atlassian’s score and lists no weakness type yet.
What to do if you cannot patch today
First, take exposed instances off the internet if you can. The advisory says “Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action.” It then offers three temporary mitigations. All three reject a request whose path contains two dots directly next to a slash, a backslash or a double colon, including URL-encoded forms of those characters.
- Option 1, every affected product: a web application firewall or proxy rule built on the regular expression Atlassian publishes.
- Option 2, Confluence, Jira Service Management, Jira, Bamboo and Crowd: enable Tomcat’s RewriteValve and add a rewrite.config that denies matching requests. The steps are per node, with a shutdown and a restart on each node of a Data Center cluster.
- Option 3, Bitbucket only: add a rule to urlrewrite.xml on every cluster node and on every Bitbucket mirror and mirror farm node.
Crucible and Fisheye appear only under Option 1, so teams running them without a firewall or reverse proxy in front have no stopgap in the advisory beyond restricting access.
How to check whether you were hit
Atlassian says it “cannot confirm if your instances have been affected by this vulnerability” and tells customers to have their security teams check every affected instance. Its guidance is to URL-decode each access-log request line, up to two decoding passes, and look for two dots next to a slash, a backslash or a double colon. The alternative is to search the raw log lines with the published regular expression.
Atlassian does not say whether any Data Center instance has been attacked. Its statement that its “investigation has not found evidence of exploitation” sits in the sentence about cloud products. A search of GitHub for the CVE identifier returned no public exploit repositories when checked on October 6.
Why it lands on a product line with an end date
Four of the eight products are on Atlassian’s Data Center end-of-life path. According to the company’s end-of-life page, Jira Software, Jira Service Management, Confluence and Crowd Data Center expire and become read-only on March 28, 2029, while Bitbucket and Bamboo Data Center will continue beyond that date. The page’s list of affected products does not include Crucible or Fisheye. Until the cutoff, Atlassian promises “Security bug-fixes for critical vulnerabilities” for Data Center products, which is what this advisory delivers.
The Register argues that the episode “rather vindicates” Atlassian’s decision to push customers into its cloud, where the fix needed no action from them. Attackers have also gone after these product families before. CISA’s Known Exploited Vulnerabilities catalog lists 13 Atlassian entries, nine of them for Confluence, and the most recent was added in November 2024. CVE-2026-21589 is not in the catalog release available to read at the time of writing, dated October 4, which predates the advisory, so its absence says nothing yet.
What is still unknown
- The root cause. Atlassian calls the bug arbitrary file access. Its filters target dot-dot sequences, the usual signature of path traversal, but the advisory does not use that term, name the affected component or say which files can be read.
- Exploitation in Data Center. None is reported, and none is ruled out.
- NVD’s own analysis. Until it arrives, the 9.3 score and the product details come from Atlassian alone.
For a look at how dot-dot filtering works and where simple versions fail, see our tutorial on preventing path traversal in Python downloads and archive extraction. Our report on GitLab’s maximum-severity path traversal flaw shows how a comparable file-access bug class looked once attackers had it.
A short checklist
- List every Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible and Fisheye instance you run, with its version, including mirrors and cluster nodes.
- Upgrade to a fixed release from the table, and check the Crowd 7.1 line against the advisory.
- Until you have, restrict external access, even for instances behind a login, and apply Option 1, 2 or 3.
- Search access logs for the patterns above. If anything matches, treat the files in that application’s web application root directory as readable and rotate any credentials kept there.








No Comment! Be the first one.