Atlassian Data Center CVE-2026-21589: critical unauthenticated file read in Jira, Confluence, Bitbucket, Bamboo and Crowd, patch now
EditorialBy TrustList Editorial
Atlassian rates CVE-2026-21589 critical (CVSS 9.3): an unauthenticated attacker can read files in the web application root of every Data Center product. Fixed versions are out; Cloud is already patched.
- Cybersecurity
- Vulnerability Management
- Patch Management
- Project Management Software
- +1 more
About Atlassian Data Center CVE-2026-21589: critical unauthenticated file read in Jira, Confluence, Bitbucket, Bamboo and Crowd, patch now
Atlassian Data Center CVE-2026-21589: critical unauthenticated file read in Jira, Confluence, Bitbucket, Bamboo and Crowd, patch now
5 October 2026 — Atlassian published a security advisory on 5 October 2026 for CVE-2026-21589, an arbitrary file access flaw that affects every self-managed Data Center product it sells: Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo and Crowd, plus Crucible and Fisheye. Atlassian rates it critical, with a CVSS 4.0 score of 9.3, and asks customers to upgrade straight away. Atlassian Cloud has already been patched and needs no action.
What the flaw does
An attacker who is not logged in can read specific files that sit inside the web application root of an affected instance. The attacker must know the exact file name and path, because the flaw does not allow directory listing. Atlassian notes that the risk rises where an installation keeps sensitive files in that location, for example configuration files with credentials. At the time of the advisory Atlassian said it had found no evidence of exploitation. Once a fix is public, the patch itself shows attackers where to look, so the window before scanning starts is usually short.
Fixed versions
Atlassian lists the following fixed releases. Every version below them is affected:
- Bitbucket Data Center 9.4.26, 10.2.8 or 10.5.1
- Confluence Data Center 9.2.26 or 10.2.19
- Jira Service Management Data Center 5.12.40, 10.3.26 or 11.3.12
- Jira Software Data Center 9.12.40, 10.3.26 or 11.3.12
- Bamboo Data Center 10.2.24 or 12.1.12
- Crowd Data Center 6.3.7, 7.0.3, 7.1.7 or 7.2.4
- Crucible 4.9.15 and Fisheye 4.9.15
If you cannot patch today
The advisory gives three interim measures. The first is to take the instance off the internet or restrict external access, including instances that only expose a login page. The second is a web application firewall or reverse-proxy rule that blocks requests where two dots sit next to a forward slash, a backslash or a double colon, including their URL-encoded forms. The third, for Confluence, Jira, Jira Service Management, Bamboo and Crowd, is a Tomcat RewriteValve with a rewrite configuration file that Atlassian supplies in the advisory. These are stop-gaps; the fix is the upgrade.
What to do
- List every Atlassian Data Center and Server instance you run, including test and disaster-recovery copies, and note its version.
- Upgrade each to the fixed release on its line. Long-term-support lines have their own fixed version, so a jump to the newest major release is not required.
- Where an upgrade needs a change window, apply one of the interim measures today and record it.
- Review web server and proxy logs for requests containing path-traversal sequences since early October.
- If a sensitive file in the web root could have been read, rotate the credentials it held.
For buyers weighing self-managed against cloud deployment of collaboration tools, this is a practical example of the difference: Cloud customers were patched before the advisory was published, while Data Center customers carry the upgrade work themselves.
Company profile on TrustList: Atlassian
Sources
Categories & features
- Cybersecurity
- Vulnerability Management
- Patch Management
- Project Management Software
- Australia
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.