Atlassian has disclosed a severe security flaw that allows unauthenticated attackers to access specific files in the web root directory of eight Data Center products that customers host themselves. Tracked as CVE-2026-21589, this issue carries a CVSS score of 9.3 out of 10. The vulnerability was officially announced on October 5, 2026. Atlassian is urging all affected users to update to patched versions immediately.
Affected Products and Scope
The vulnerability impacts the self-hosted Data Center editions of Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye. Cloud-hosted Atlassian products were already patched and are not vulnerable. Bitbucket Cloud, in particular, is not affected.
For each product, versions released before the fixed releases are vulnerable. Users should upgrade to the fixed versions listed: Bitbucket Data Center to at least 9.4.26 / 10.2.8 / 10.5.1; Confluence Data Center to 9.2.26 / 10.2.19; Jira Software Data Center to 9.12.40 / 10.3.26 / 11.3.12; Jira Service Management Data Center to 5.12.40 / 10.3.26 / 11.3.12; Bamboo Data Center to 10.2.24 / 12.1.12; Crowd Data Center to 6.3.7 / 7.0.3 / 7.1.7 / 7.2.4; Crucible and Fisheye Data Center to 4.9.15 apiece. Versions older than those are vulnerable.
Nature of the Vulnerability and Mitigations
CVE-2026-21589 is identified as a path traversal vulnerability. It lets an attacker, without login credentials, read files if they know the exact filename and path relative to the web application root. The flaw doesn’t allow listing of directory contents—only access to known paths. Some of those paths may host sensitive information depending on the server configuration.
While waiting to upgrade, Atlassian is recommending temporary mitigations. All affected products can enforce a firewall rule—via WAF or reverse proxy—that blocks URLs containing “..” directly adjacent to “/”, “\\”, or “::”. Some products also support other methods: Confluence, Jira, Bamboo, and Crowd can use a Tomcat RewriteValve rule; Bitbucket can use a urlrewrite.xml rule. Crucible and Fisheye only support the firewall or reverse proxy mitigation. These temporary measures are not substitutes for the updates.
What Users Should Do Now
Atlassian’s cloud customers are already safe. For self-hosted Data Center instances exposed to the internet, administrators should immediately upgrade to the fixed versions. If that’s not immediately possible, deploy one of the mitigation rules listed. Restricting network access or taking the instance offline is advised if it’s publicly reachable after authentication.
Admins are also urged to search access logs for evidence of exploitation. Atlassian suggests decoding request lines up to two times and scanning for patterns such as “..” directly next to “/”, “\\”, or “::”. This helps detect attempts to exploit the vulnerability. It’s unknown whether there have been actual attacks so far; the advisory states there’s no confirmed exploitation to date.
This isn’t the first time a path traversal flaw has hit Atlassian. A similar vulnerability (CVE-2021-26086) allowed remote attackers to read files on Jira Server and Data Center platforms. That earlier bug was listed among known exploited vulnerabilities.
The high severity of this vulnerability underscores how exposed self-hosted infrastructure can be even when authentication is required. Administrators need to act quickly—not just to patch, but to verify whether their systems have been targeted. Regular audits, stricter access restrictions, and keeping up with security advisories are essential. What comes next is not only reinforcing defences but anticipating where those defences will be tested again.