DKDKCISSPSearch
VulnerabilitiesDEVELOPING

Atlassian warns of critical file-access flaw in Jira, Confluence

Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket.

DKCISSP News DeskBleepingComputer6 Oct 2026, 11:04 pm
Atlassian warns of critical file-access flaw in Jira, Confluence
Image courtesy of BleepingComputer. Original report
DKCISSP REPORT

Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket.

CVE-2026-21589, a critical arbitrary file access vulnerability with a 9.3 CVSS score, affects all versions of Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.

CVE-2026-21589 affects all product versions released before the releases listed below, which address the vulnerability: Atlassian urges system administrators who manage self-hosted instances to apply the security updates immediately.

Attackers who know where to look can read files from Atlassian Data Center installations without logging in, the company has warned.

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory.

CVE-2021-26086 is a path traversal vulnerability in Jira Server and Data Center that allows remote attackers to read specific files.

Atlassian said it currently has no evidence that CVE-2026-21589 is being exploited in attacks, but urges administrators to review access logs for the traversal patterns described in the bulletin.

If immediate patching is not possible, the company recommends restricting external network access, including for internet-facing instances that require user authentication.

Atlassian disclosed the flaw , CVE-2026-21589 , on October 5, rated it 9.3 out of 10, and listed a fixed version for each product.

The security issue allows an unauthenticated attacker to access specific files within an affected application's web root directory.

What happened

Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket.

CVE-2026-21589, a critical arbitrary file access vulnerability with a 9.3 CVSS score, affects all versions of Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.

What changed

CVE-2026-21589 affects all product versions released before the releases listed below, which address the vulnerability: Atlassian urges system administrators who manage self-hosted instances to apply the security updates immediately.

Attackers who know where to look can read files from Atlassian Data Center installations without logging in, the company has warned.

Who is affected

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory.

CVE-2021-26086 is a path traversal vulnerability in Jira Server and Data Center that allows remote attackers to read specific files.

Why it matters

Atlassian said it currently has no evidence that CVE-2026-21589 is being exploited in attacks, but urges administrators to review access logs for the traversal patterns described in the bulletin.

If immediate patching is not possible, the company recommends restricting external network access, including for internet-facing instances that require user authentication.

Technical details

Atlassian disclosed the flaw , CVE-2026-21589 , on October 5, rated it 9.3 out of 10, and listed a fixed version for each product.

The security issue allows an unauthenticated attacker to access specific files within an affected application's web root directory.

The advisory does not mention whether the flaw has been exploited against Data Center instances, or who discovered it.

Response

Temporary mitigations include adding a web application firewall (WAF) or proxy rule blocking specified traversal patterns across all affected products, Tomcat RewriteValve rules for Confluence, JSM, Jira, Bamboo, and Crowd, or a URL rewrite rule for Bitbucket.

Atlassian's cloud products affected by the flaw have already been patched, and cloud customers do not need to take any action.

What security teams should do

Cloud customers need to take no action, as the vendor has automatically patched the products.

According to the company, the affected cloud products have been patched, its investigation found no evidence of exploitation, and customers using them do not need to take any action.

Attribution

BleepingComputer: Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket.

Help Net Security: Attackers who know where to look can read files from Atlassian Data Center installations without logging in, the company has warned.

The Hacker News: A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN VULNERABILITIES

More cybersecurity reporting

Red Hat’s Lightwell Project Remediates 400 Open-Source VulnerabilitiesInfosecurity Magazine · 6 Oct 2026, 6:31 pmDell System Update flaw allows attackers to gain root privileges (CVE-2026-86360) - Help Net SecurityHelp Net Security · 6 Oct 2026, 4:14 pmAttackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCEThe Hacker News · 5 Oct 2026, 8:48 pmOut-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940) - Help Net SecurityHelp Net Security · 5 Oct 2026, 4:08 pm