Atlassian Warns of Critical File-Access Flaw in Jira, Confluence

· Original article ↗

Summary

CVE-2026-21589 lets unauthenticated attackers access specific files in the web roots of affected self-hosted Atlassian Data Center products if they know the exact file path. Atlassian released fixes and temporary mitigations.

Key points

  • CVE-2026-21589 affects self-hosted Atlassian Data Center products including Bitbucket, Confluence, Jira, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye.
  • An unauthenticated attacker can access specific files in an affected application's web root, but must know the exact file name and path; the flaw does not allow directory listing.
  • Atlassian released fixed versions for the affected products and urges administrators to apply the updates immediately.
  • Cloud customers require no action because Atlassian has automatically patched the products.
  • If patching is delayed, Atlassian recommends restricting external access and applying product-specific WAF, proxy, or URL-rewrite mitigations across all cluster nodes.
  • Atlassian reports no evidence of exploitation, but recommends checking access logs for the traversal patterns in its advisory.

Article Details

Vulnerability Types
  • Arbitrary file access within the web application root directory
  • Path traversal
Severity
critical
Affected Versions
  • Bitbucket Data Center: versions released before the security releases 9.4.26, 10.2.8, and 10.5.1
  • Confluence Data Center: versions released before the security releases 9.2.26 and 10.2.19
  • Jira Service Management Data Center: versions released before the security releases 5.12.40, 10.3.26, and 11.3.12
  • Jira Software Data Center: versions released before the security releases 9.12.40, 10.3.26, and 11.3.12
  • Bamboo Data Center: versions released before the security releases 10.2.24 and 12.1.12
  • Crowd Data Center: versions released before the security releases 6.3.7, 7.0.3, 7.1.7, and 7.2.4
  • Crucible: versions released before 4.9.15
  • Fisheye: versions released before 4.9.15
Exploitation Status
not_reported
Exploit Availability
unknown
Patch Status
available
Workarounds
  • Restrict external network access to affected self-hosted instances.
  • Add a web application firewall or proxy rule blocking the specified traversal patterns.
  • Apply Tomcat RewriteValve rules for Confluence, Jira Service Management, Jira, Bamboo, and Crowd.
  • Apply a URL rewrite rule for Bitbucket.

CVE

Vendors

Products

Related Articles