CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products
Atlassian patched CVE-2026-21589, an unauthenticated file-read flaw in eight products, with public proof-of-concept code available.
On October 5, 2026, Atlassian disclosed CVE-2026-21589, a CVSS 9.3 unauthenticated arbitrary file-access flaw affecting Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye. watchTowr found double-colon sequences become path separators during web-resource handling, allowing reads throughout the application web root but not outside the Tomcat context. A public Python file-read proof-of-concept and Nuclei template are available. Cloud products are already patched; on-premises customers should upgrade to the listed fixed versions, treat WAF rules as temporary, and search access logs for encoded traversal.
- CVE-2026-21589 scores CVSS 9.3 and allows unauthenticated web-root file reads.
- Double-colon sequences become path separators in Atlassian web-resource handling.
- Public Python proof-of-concept and Nuclei template cover Jira, Confluence, and Bitbucket.
- Atlassian Cloud is patched; Data Center customers must upgrade or isolate systems.
- Reading crowd.properties can expose credentials usable to create administrators.
Vulnerabilities mentionedAll →
- CVE-2026-215899.32%This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access…published PoC ×7
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21589 | This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access… |
Full article585 words · extracted from rapid7.com · click to collapse
Overview
On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589, a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3. An unauthenticated remote attacker who knows a target file's exact name and path can access it within the application's web root; the vulnerability does not provide directory listing or enumeration.
Atlassian's advisory treats all versions before the applicable fixed releases as affected, including unsupported versions. Affected Atlassian Cloud products have already been patched, and no action is required from Cloud customers.
Detailed technical analysis and file-read proof-of-concept scripts are public, so Rapid7 recommends patching on an emergency basis, outside of normal patch cycles, and reviewing access logs for attempted exploitation.
Technical overview
NVD lists files or directories accessible to external parties (CWE-552) as the weakness associated with CVE-2026-21589.
On October 6, watchTowr Labs published a technical analysis based on comparisons of vulnerable and patched Jira, Confluence, and Bitbucket packages. Their analysis identified a path traversal vulnerability in Atlassian's web-resource handling: double-colon (::) sequences can become path separators during request processing, allowing traversal components to reach the resource-loading code, resulting in the contents of arbitrary file being read back to an attacker.
Their testing could not traverse outside the Tomcat context, but could read files throughout the application web root. In an Atlassian Crowd deployment that had Jira configured, reading WEB-INF/classes/crowd.properties exposed application credentials. With network access to Crowd, they used those credentials to create a user and add it to jira-administrators; Crowd's IP allowlisting can block this direct route.
Mitigation guidance
Organizations should upgrade each affected installation to a listed fixed version or the latest available version. Atlassian's October 5 advisory lists the following fixed versions:
Product | Fixed versions |
|---|---|
Bitbucket Data Center | 9.4.26, 10.2.8, 10.5.1 |
Confluence Data Center | 9.2.26, 10.2.19 |
Jira Service Management Data Center | 5.12.40, 10.3.26, 11.3.12 |
Jira Software Data Center | 9.12.40, 10.3.26, 11.3.12 |
Bamboo Data Center | 10.2.24, 12.1.12 |
Crowd Data Center | 6.3.7, 7.0.3, 7.1.7, 7.2.4 |
Crucible | 4.9.15 |
Fisheye | 4.9.15 |
Organizations unable to patch immediately should remove affected instances from the internet or otherwise restrict them from external network access. Atlassian provides a Web Application Firewall or proxy rule for all affected products, a Tomcat RewriteValve mitigation for Confluence, Jira Service Management, Jira Software, Bamboo, and Crowd, and a separate urlrewrite.xml rule for Bitbucket. These mitigations are limited and are not replacements for patching.
Rapid7 strongly recommends looking for signs of compromise even after the patch has been applied. Atlassian recommends URL-decoding each access-log request line up to twice, then searching for .. immediately adjacent to /, \, or ::. Alternatively, search raw logs with the vendor-supplied regex:
(?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).*Public testing artifacts for Jira, Confluence, and Bitbucket include a Python file-read PoC and a Nuclei template. If investigation identifies access to protected configuration files, organizations should rotate exposed credentials and other secrets after containing the affected systems.
For the latest mitigation and investigation guidance, please refer to the vendor security advisory.
Rapid7 customers
Exposure Command, Vulnerability Management, and Nexpose
Exposure Command, Vulnerability Management, and Nexpose customers can assess exposure to CVE-2026-21589 with unauthenticated vulnerability checks on Jira Software Data Center expected to be available in the October 8 content release.
Updates
October 7, 2026: Initial publication.