Atlassian has disclosed a critical vulnerability affecting eight self-hosted Data Center products that could allow an unauthenticated attacker to read specific files from the web application root directory.

Tracked as CVE-2026-21589, the vulnerability has been rated 9.3 out of 10 (Critical) using CVSS 4.0.

The flaw affects Atlassian products that customers host themselves, including Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye.

Atlassian has released fixed versions for all affected products and recommends that customers upgrade as soon as possible.

CVE-2026-21589: Atlassian Arbitrary File Access

The vulnerability allows an attacker with no authentication or login access to read specific files located within the application's web root directory.

However, exploitation requires the attacker to already know the exact filename and path of the targeted file.

The vulnerability does not provide directory listing capabilities.

Atlassian describes the issue as a path traversal vulnerability, where specially crafted paths can potentially allow requests to access files outside their intended location.

The web application root directory contains the application's own files and, depending on the deployment configuration, may contain sensitive information.

Atlassian warned that the vulnerability could therefore result in the disclosure of sensitive files.

Affected Atlassian Products

The vulnerability affects the following Data Center products:

Product Fixed Versions
Bitbucket Data Center 9.4.26, 10.2.8, 10.5.1
Confluence Data Center 9.2.26, 10.2.19
Jira Software Data Center 9.12.40, 10.3.26, 11.3.12
Jira Service Management Data Center 5.12.40, 10.3.26, 11.3.12
Bamboo Data Center 10.2.24, 12.1.12
Crowd Data Center 6.3.7, 7.0.3, 7.1.7, 7.2.4
Crucible 4.9.15
Fisheye 4.9.15

Atlassian noted that the vulnerability may also affect versions that have reached end of life.

Customers are advised to upgrade to a fixed Long Term Support (LTS) release or a later version where possible.

Atlassian Cloud Customers

Atlassian stated that its cloud products have already been patched.

Cloud customers therefore do not need to take any action related to CVE-2026-21589.

The vulnerability primarily affects self-hosted Data Center deployments.

Path Traversal Attack

Atlassian identifies the underlying issue as a path traversal vulnerability.

Path traversal vulnerabilities occur when an application fails to properly restrict file paths supplied through a request.

An attacker can potentially manipulate a path to access files outside the application's intended directory.

For CVE-2026-21589, Atlassian said an attacker must know the exact path and filename they want to access.

The vulnerability does not allow attackers to simply list the contents of the target directory.

Nevertheless, the company considers the vulnerability critical because sensitive files may exist within affected application directories.

Temporary Mitigations

Atlassian recommends upgrading affected systems immediately.

For organizations that cannot upgrade immediately, Atlassian recommends taking the affected instance offline where possible.

Any instance accessible from the public internet, including instances that require authentication, should be restricted from external network access until the system can be upgraded or an appropriate blocking rule is deployed.

Atlassian provides three temporary mitigation options.

Web Application Firewall or Reverse Proxy

All eight affected products can use a rule on a Web Application Firewall (WAF) or reverse proxy to block malicious URL patterns.

The blocking rule is designed to prevent requests containing path traversal sequences involving:

../
..\
..::

including URL-encoded variations.

Tomcat RewriteValve

The following products can also use a Tomcat RewriteValve rule:

  • Confluence
  • Jira Software
  • Jira Service Management
  • Bamboo
  • Crowd

The rule must be installed on every applicable node, followed by a shutdown and restart.

Bitbucket URL Rewrite

Bitbucket deployments can use a rule in:

urlrewrite.xml

The configuration must be applied to every relevant node, mirror, and mirror-farm node, followed by a restart.

Crucible and Fisheye have the WAF/reverse-proxy mitigation available.

Atlassian emphasizes that these mitigations are not a replacement for patching.

How to Check for Exploitation

Atlassian said its investigation has found no evidence of exploitation against its cloud products.

However, the company did not confirm whether attacks against vulnerable self-hosted instances have occurred.

Organizations should review their application and reverse-proxy access logs for suspicious path traversal requests.

Atlassian recommends URL-decoding request lines up to two times and looking for traversal sequences involving:

../
..\
..::

Security teams can also search raw logs using Atlassian's recommended blocking pattern.

Organizations should investigate suspicious requests discovered in historical logs, particularly requests targeting sensitive or known application files.

Previous Atlassian Path Traversal Vulnerabilities

This is not the first Atlassian product to be affected by a path traversal vulnerability.

For example, CVE-2021-26086 affected Jira Server and Data Center and could allow remote attackers to read specific files.

The vulnerability was later added to the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities (KEV) catalog.

This history makes rapid remediation particularly important for organizations exposing Atlassian infrastructure to the internet.

CVSS 9.3 Critical Severity

Atlassian assigned CVE-2026-21589 a CVSS 4.0 score of 9.3, classifying it as critical.

The score reflects several significant characteristics:

  • Network-reachable exploitation
  • No authentication required
  • No user interaction required
  • High impact to confidentiality
  • Potential impact beyond the directly vulnerable system

Atlassian's advisory does not publicly identify the exact sensitive files that could be accessed or all configurations in which sensitive information may be present.

The company recommends that organizations evaluate the vulnerability based on their individual deployment and exposure.

Security Recommendations

Organizations running affected Atlassian Data Center products should:

  • Upgrade to a fixed version immediately.
  • Restrict public internet access to vulnerable instances.
  • Take vulnerable instances offline where practical.
  • Deploy Atlassian's temporary blocking rules if immediate patching is impossible.
  • Review WAF and reverse-proxy logs for path traversal attempts.
  • Review application access logs for suspicious file-access requests.
  • Investigate historical requests containing encoded traversal sequences.
  • Review exposed application directories for sensitive files.
  • Ensure all nodes in clustered deployments are patched.
  • Remove unnecessary internet exposure from Atlassian administrative infrastructure.

Key Takeaway

CVE-2026-21589 is a critical unauthenticated file-access vulnerability affecting eight Atlassian Data Center products.

Although exploitation requires knowledge of the exact target file path and filename, the vulnerability can expose sensitive information from self-hosted Atlassian environments.

Organizations should prioritize patching over temporary mitigations and review historical logs for evidence of exploitation.

Given the widespread use of Jira, Confluence, Bitbucket, and other Atlassian products in enterprise environments, publicly accessible and unpatched instances should be treated as a high-priority security risk.