Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products
Atlassian patched CVE-2026-21589, a CVSS 9.3 unauthenticated file-access flaw in eight Data Center products.
Atlassian disclosed CVE-2026-21589, a critical arbitrary file-access flaw rated CVSS 9.3, affecting eight Data Center products including Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye. Unauthenticated attackers who know an exact file name and path can read files in the application web root, but cannot list directories. Fixed releases are available for each product, and Atlassian Cloud is already patched. The vendor reports no evidence of exploitation and offers temporary WAF or Tomcat RewriteValve mitigations until upgrades are applied.
- CVE-2026-21589 scores CVSS 9.3 and requires no authentication.
- Eight Data Center products are affected, including Jira, Confluence, and Bitbucket.
- Attackers must know the exact file path and cannot list directories.
- Atlassian found no exploitation evidence; Atlassian Cloud is already patched.
- WAF or Tomcat RewriteValve rules are temporary and do not replace patching.
Vulnerabilities mentionedAll →
- CVE-2026-215899.32%This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access…published PoC ×7
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21589 | This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access… |
Full article509 words · extracted from cybersecuritynews.com · click to collapse
Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence, and Bitbucket. Tracked as CVE-2026-21589, the flaw has a CVSS score of 9.3. It lets unauthenticated attackers access specific files in an affected application’s web root directory.
The advisory, published on October 5, 2026, covers Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye.
Atlassian urges customers running affected installations to patch immediately. The vulnerability exposes files within the web application root directory without requiring an attacker to sign in.
However, exploitation requires knowing the target file’s exact name and path. Attackers cannot use this flaw to list directory contents or automatically discover available files.
This limitation narrows the attack, but does not remove the danger. Atlassian warns that some configurations may store sensitive files in accessible locations, increasing the impact of a successful exploit.
The disclosed behavior concerns file access it should not be interpreted as confirmed unrestricted access to every file on the underlying server.
Atlassian Patches Critical Vulnerabilities
Atlassian describes all unpatched versions of the listed products as affected. Older installations outside the vendor’s support window may also be vulnerable, so organizations maintaining legacy deployments should upgrade to supported, fixed releases.
For Jira Software Data Center, the fixed releases are 9.12.40, 10.3.26, and 11.3.12. Jira Service Management Data Center users should upgrade to 5.12.40, 10.3.26, or 11.3.12. Confluence Data Center fixes are available in 9.2.26 and 10.2.19.
Bitbucket Data Center customers should install 9.4.26, 10.2.8, or 10.5.1. Bamboo Data Center fixes are available in 10.2.24 and 12.1.12. The advisory lists Crowd Data Center fixes as 6.3.7, 7.0.3, 7.1.7, and 7.2.4. Crucible and Fisheye users should upgrade to 4.9.15.
Administrators should use Atlassian’s product advisory when selecting their upgrade target. Each affected installation needs attention; updating one product does not address vulnerable deployments of the others.
Atlassian recommends installing a listed fixed release or the latest version. Organizations unable to patch immediately should remove affected instances from the public internet where possible.
Atlassian says externally accessible installations require restrictions even when user authentication protects normal application access, because exploitation does not require authenticated access.
One temporary option is a web application firewall or reverse proxy rule using Atlassian-supplied regular expressions. The rule blocks traversal patterns involving adjacent dots and path separators, including encoded variants. Administrators must test that their implementation handles the specified patterns correctly.
Another option uses Tomcat’s RewriteValve with Atlassian-supplied rewrite configuration. Administrators should back up the instance, stop each cluster node, enable the valve, install the configuration, and restart the node. These measures are temporary and not a substitute for patching.
Atlassian says affected Cloud products have already been patched, with no customer action required. Its investigation found no evidence of exploitation.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.