Atlassian has highlighted a significant security concern impacting several of its widely used products, including Jira, Confluence, and Bitbucket. The vulnerability, identified as CVE-2026-21589, has been assigned a high severity rating with a CVSS score of 9.3. This issue allows attackers without authentication to access certain files located in the web root directory of the affected applications.
Details of the Vulnerability
In a security advisory released on October 5, 2026, Atlassian specified that the flaw affects Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. The vulnerability permits unauthorized file access, posing a risk to sensitive data stored within the application’s directory structure.
Exploitation of this flaw requires knowledge of the exact file name and path but does not allow directory listing or automatic file detection. Despite this limitation, Atlassian cautions that certain configurations might expose sensitive files, enhancing the potential impact of an exploit.
Patch Recommendations and Product Updates
Atlassian strongly advises customers using affected versions to implement patches without delay. The company has issued updates for Jira Software Data Center, with fixed versions being 9.12.40, 10.3.26, and 11.3.12. Jira Service Management Data Center should move to 5.12.40, 10.3.26, or 11.3.12, while Confluence Data Center updates are available in 9.2.26 and 10.2.19.
For Bitbucket Data Center, updates include versions 9.4.26, 10.2.8, and 10.5.1. Bamboo Data Center has fixes in 10.2.24 and 12.1.12. Crowd Data Center updates are available in versions 6.3.7, 7.0.3, 7.1.7, and 7.2.4. Crucible and Fisheye users should upgrade to 4.9.15. Administrators should refer to Atlassian’s advisory to choose the correct upgrade path for each product.
Temporary Mitigation Measures
Organizations unable to immediately apply patches should consider alternative protective measures. These include removing affected installations from public access or implementing a web application firewall. Atlassian provides specific regular expressions for firewall rules to block dangerous file traversal patterns.
Additionally, administrators may deploy Tomcat’s RewriteValve with a supplied rewrite configuration to mitigate risks temporarily. However, these methods are not substitutes for proper patching. Atlassian confirms that its Cloud products have been patched, requiring no action from customers. There is currently no evidence of the vulnerability being exploited in the wild.
Addressing these vulnerabilities promptly is crucial to maintaining security and safeguarding sensitive information within Atlassian’s suite of products.
