Skip to content
TrustList
News

Atlassian Data Center CVE-2026-21589: critical unauthenticated file read in Jira, Confluence, Bitbucket, Bamboo and Crowd, patch now

Editorial

By TrustList Editorial

Atlassian rates CVE-2026-21589 critical (CVSS 9.3): an unauthenticated attacker can read files in the web application root of every Data Center product. Fixed versions are out; Cloud is already patched.

About Atlassian Data Center CVE-2026-21589: critical unauthenticated file read in Jira, Confluence, Bitbucket, Bamboo and Crowd, patch now

Atlassian Data Center CVE-2026-21589: critical unauthenticated file read in Jira, Confluence, Bitbucket, Bamboo and Crowd, patch now

5 October 2026 — Atlassian published a security advisory on 5 October 2026 for CVE-2026-21589, an arbitrary file access flaw that affects every self-managed Data Center product it sells: Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo and Crowd, plus Crucible and Fisheye. Atlassian rates it critical, with a CVSS 4.0 score of 9.3, and asks customers to upgrade straight away. Atlassian Cloud has already been patched and needs no action.

What the flaw does

An attacker who is not logged in can read specific files that sit inside the web application root of an affected instance. The attacker must know the exact file name and path, because the flaw does not allow directory listing. Atlassian notes that the risk rises where an installation keeps sensitive files in that location, for example configuration files with credentials. At the time of the advisory Atlassian said it had found no evidence of exploitation. Once a fix is public, the patch itself shows attackers where to look, so the window before scanning starts is usually short.

Fixed versions

Atlassian lists the following fixed releases. Every version below them is affected:

  • Bitbucket Data Center 9.4.26, 10.2.8 or 10.5.1
  • Confluence Data Center 9.2.26 or 10.2.19
  • Jira Service Management Data Center 5.12.40, 10.3.26 or 11.3.12
  • Jira Software Data Center 9.12.40, 10.3.26 or 11.3.12
  • Bamboo Data Center 10.2.24 or 12.1.12
  • Crowd Data Center 6.3.7, 7.0.3, 7.1.7 or 7.2.4
  • Crucible 4.9.15 and Fisheye 4.9.15

If you cannot patch today

The advisory gives three interim measures. The first is to take the instance off the internet or restrict external access, including instances that only expose a login page. The second is a web application firewall or reverse-proxy rule that blocks requests where two dots sit next to a forward slash, a backslash or a double colon, including their URL-encoded forms. The third, for Confluence, Jira, Jira Service Management, Bamboo and Crowd, is a Tomcat RewriteValve with a rewrite configuration file that Atlassian supplies in the advisory. These are stop-gaps; the fix is the upgrade.

What to do

  1. List every Atlassian Data Center and Server instance you run, including test and disaster-recovery copies, and note its version.
  2. Upgrade each to the fixed release on its line. Long-term-support lines have their own fixed version, so a jump to the newest major release is not required.
  3. Where an upgrade needs a change window, apply one of the interim measures today and record it.
  4. Review web server and proxy logs for requests containing path-traversal sequences since early October.
  5. If a sensitive file in the web root could have been read, rotate the credentials it held.

For buyers weighing self-managed against cloud deployment of collaboration tools, this is a practical example of the difference: Cloud customers were patched before the advisory was published, while Data Center customers carry the upgrade work themselves.

Company profile on TrustList: Atlassian

Sources

Categories & features