Atlassian warns of critical file-access flaw in Jira, Confluence
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket.

Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket.
CVE-2026-21589, a critical arbitrary file access vulnerability with a 9.3 CVSS score, affects all versions of Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.
CVE-2026-21589 affects all product versions released before the releases listed below, which address the vulnerability: Atlassian urges system administrators who manage self-hosted instances to apply the security updates immediately.
Attackers who know where to look can read files from Atlassian Data Center installations without logging in, the company has warned.
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory.
CVE-2021-26086 is a path traversal vulnerability in Jira Server and Data Center that allows remote attackers to read specific files.
Atlassian said it currently has no evidence that CVE-2026-21589 is being exploited in attacks, but urges administrators to review access logs for the traversal patterns described in the bulletin.
If immediate patching is not possible, the company recommends restricting external network access, including for internet-facing instances that require user authentication.
Atlassian disclosed the flaw , CVE-2026-21589 , on October 5, rated it 9.3 out of 10, and listed a fixed version for each product.
The security issue allows an unauthenticated attacker to access specific files within an affected application's web root directory.
What happened
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket.
CVE-2026-21589, a critical arbitrary file access vulnerability with a 9.3 CVSS score, affects all versions of Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.
What changed
CVE-2026-21589 affects all product versions released before the releases listed below, which address the vulnerability: Atlassian urges system administrators who manage self-hosted instances to apply the security updates immediately.
Attackers who know where to look can read files from Atlassian Data Center installations without logging in, the company has warned.
Who is affected
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory.
CVE-2021-26086 is a path traversal vulnerability in Jira Server and Data Center that allows remote attackers to read specific files.
Why it matters
Atlassian said it currently has no evidence that CVE-2026-21589 is being exploited in attacks, but urges administrators to review access logs for the traversal patterns described in the bulletin.
If immediate patching is not possible, the company recommends restricting external network access, including for internet-facing instances that require user authentication.
Technical details
Atlassian disclosed the flaw , CVE-2026-21589 , on October 5, rated it 9.3 out of 10, and listed a fixed version for each product.
The security issue allows an unauthenticated attacker to access specific files within an affected application's web root directory.
The advisory does not mention whether the flaw has been exploited against Data Center instances, or who discovered it.
Response
Temporary mitigations include adding a web application firewall (WAF) or proxy rule blocking specified traversal patterns across all affected products, Tomcat RewriteValve rules for Confluence, JSM, Jira, Bamboo, and Crowd, or a URL rewrite rule for Bitbucket.
Atlassian's cloud products affected by the flaw have already been patched, and cloud customers do not need to take any action.
What security teams should do
Cloud customers need to take no action, as the vendor has automatically patched the products.
According to the company, the affected cloud products have been patched, its investigation found no evidence of exploitation, and customers using them do not need to take any action.
Attribution
BleepingComputer: Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket.
Help Net Security: Attackers who know where to look can read files from Atlassian Data Center installations without logging in, the company has warned.
The Hacker News: A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory.
What to watch next
Watch for new exploitation reports and updated indicators of compromise.
Watch for updated vendor guidance and fixed-version details.