Atlassian warns of critical file-access flaw in Jira, Confluence
At a glance
- Severity
- Medium
- Used in attacks
- Not on CISA’s list
- Flaws named
- CVE-2026-21589
- Vendors and products
- AtlassianConfluence
- Industries
- SaaS & technology
- Reported by
- 1 outlet
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket.
The security issue allows an unauthenticated attacker to access specific files within an affected application's web root directory. However, exploitation requires knowing the exact name of the file and path.
“This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions,” reads the security advisory.
“Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents,” Atlassian says.
CVE-2026-21589 affects all product versions released before the releases listed below, which address the vulnerability:
- Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1
- Confluence Data Center: 9.2.26, 10.2.19
- Jira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12
- Jira Software Data Center: 9.12.40, 10.3.26, 11.3.12
- Bamboo Data Center: 10.2.24, 12.1.12
- Crowd Data Center: 6.3.7, 7.0.3, 7.1.7, 7.2.4
- Crucible: 4.9.15
- Fisheye: 4.9.15
Atlassian urges system administrators who manage self-hosted instances to apply the security updates immediately. Cloud customers need to take no action, as the vendor has automatically patched the products.
If immediate patching is not possible, the company recommends restricting external network access, including for internet-facing instances that require user authentication.
Temporary mitigations include adding a web application firewall (WAF) or proxy rule blocking specified traversal patterns across all affected products, Tomcat RewriteValve rules for Confluence, JSM, Jira, Bamboo, and Crowd, or a URL rewrite rule for Bitbucket.
Atlassian's advisory offers step-by-step instructions and configuration details to implement the recommended temporary mitigations.
The changes must cover every cluster node, including Bitbucket mirrors and mirror farm nodes.
Atlassian said it currently has no evidence that CVE-2026-21589 is being exploited in attacks, but urges administrators to review access logs for the traversal patterns described in the bulletin.
The vendor says it cannot determine whether individual customer instances have been compromised, urging customers using self-hosted instances to engage with their local security team.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Originally published by BleepingComputer. © BleepingComputer. Written by Bill Toulas.
Vulnerabilities referenced
- CVE-2026-21589Not scored yet
Product not named yet
h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. h3. Context This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. h3. Details: * The vulnerability must be addressed for affected versions of: Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.1, 7.2.4 Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 Crucible, fix versions 4.9.15 Fisheye, fix version 4.9.15 * Exploitation requires prior knowledge of the target file's exact name and path. * The vulnerability does not include the capability to enumerate or list directory contents.
Full record →
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-10-06 17:34 UTC
Related stories
- Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
The Hacker News · 2026-10-07
- PoeLLM malware infects exposed AI servers in cryptomining attacks
BleepingComputer · 2026-10-07
- Hackers exploit critical Atlassian flaw after public PoC release
BleepingComputer · 2026-10-07
- FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
The Hacker News · 2026-10-07
- Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
The Hacker News · 2026-10-07