Atlassian Warns of Critical File-Access Flaw in Jira, Confluence

Summary
CVE-2026-21589 lets unauthenticated attackers access specific files in the web roots of affected self-hosted Atlassian Data Center products if they know the exact file path. Atlassian released fixes and temporary mitigations.
Key points
- CVE-2026-21589 affects self-hosted Atlassian Data Center products including Bitbucket, Confluence, Jira, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye.
- An unauthenticated attacker can access specific files in an affected application's web root, but must know the exact file name and path; the flaw does not allow directory listing.
- Atlassian released fixed versions for the affected products and urges administrators to apply the updates immediately.
- Cloud customers require no action because Atlassian has automatically patched the products.
- If patching is delayed, Atlassian recommends restricting external access and applying product-specific WAF, proxy, or URL-rewrite mitigations across all cluster nodes.
- Atlassian reports no evidence of exploitation, but recommends checking access logs for the traversal patterns in its advisory.
Article Details
- Vulnerability Types
- Arbitrary file access within the web application root directory
- Path traversal
- Severity
- critical
- Affected Versions
- Bitbucket Data Center: versions released before the security releases 9.4.26, 10.2.8, and 10.5.1
- Confluence Data Center: versions released before the security releases 9.2.26 and 10.2.19
- Jira Service Management Data Center: versions released before the security releases 5.12.40, 10.3.26, and 11.3.12
- Jira Software Data Center: versions released before the security releases 9.12.40, 10.3.26, and 11.3.12
- Bamboo Data Center: versions released before the security releases 10.2.24 and 12.1.12
- Crowd Data Center: versions released before the security releases 6.3.7, 7.0.3, 7.1.7, and 7.2.4
- Crucible: versions released before 4.9.15
- Fisheye: versions released before 4.9.15
- Exploitation Status
- not_reported
- Exploit Availability
- unknown
- Patch Status
- available
- Workarounds
- Restrict external network access to affected self-hosted instances.
- Add a web application firewall or proxy rule blocking the specified traversal patterns.
- Apply Tomcat RewriteValve rules for Confluence, Jira Service Management, Jira, Bamboo, and Crowd.
- Apply a URL rewrite rule for Bitbucket.
CVE
Vendors
Products
Bamboo Data CenterBamboo Data Center: 10.2.24, 12.1.12Bitbucket Data CenterBitbucket Data Center: 9.4.26, 10.2.8, 10.5.1Confluence Data CenterConfluence Data Center: 9.2.26, 10.2.19Crowd Data CenterCrowd Data Center: 6.3.7, 7.0.3, 7.1.7, 7.2.4CrucibleCrucible: 4.9.15FisheyeFisheye: 4.9.15Jira Service Management Data CenterJira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12Jira Software Data CenterJira Software Data Center: 9.12.40, 10.3.26, 11.3.12