Technology·News & analysis
Atlassian warns of a critical file access flaw in Jira, Confluence and six more Data Center products
CVE-2026-21589 lets an unauthenticated attacker read files from the web root of self-hosted Atlassian servers. Fixes are out, and Atlassian says to take exposed instances offline if you can't patch yet.

Tide
Ripple
Sci-fi
1/10
Reality
Shipping
Know the file's name, and the server hands it over.How we rate
Atlassian's Jira, Confluence and Bitbucket run a huge share of corporate engineering and IT work, and many large organizations still host them on their own servers.
This flaw lets an attacker with no login read files from those servers, and Atlassian warns some setups hold sensitive files there. Fixed versions are out now. If your company self-hosts any Atlassian product, it needs to upgrade or take exposed instances off the internet.
What to know
- Atlassian disclosed CVE-2026-21589, an arbitrary file access flaw it rates Critical at 9.3, in the self-hosted Data Center versions of eight products.
- Affected: Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. Atlassian says all versions before the fixed releases are vulnerable.
- An unauthenticated attacker can read specific files in the web application root, but only if they know the exact file name and path. Directory listing isn't possible.
- Atlassian Cloud is already patched and the company found no evidence of exploitation there. Data Center admins must upgrade, or cut internet access and apply a firewall or rewrite rule.
Atlassian is telling customers who run its software on their own servers to patch now. A new critical flaw, CVE-2026-21589, lets an attacker with no login read files from Jira, Confluence, Bitbucket and five other self-hosted products.
The company published its security advisory on Monday, October 5. It also emailed users with a message that opens with the words "Action required," The Register reports.
What's the vulnerability?
CVE-2026-21589 is an arbitrary file access bug. According to Atlassian, it "allows an unauthenticated attacker to access specific files within the web application root directory in affected versions."
How bad: Atlassian rates it Critical, with a CVSS score of 9.3. The company stresses that this is its own assessment and that customers should judge how it applies to their environment.
The limits: exploitation requires prior knowledge of the target file's exact name and path. The flaw also does not let attackers list or enumerate what's in a directory.
The catch: "In some configurations, there may be sensitive files present that increase your risk," Atlassian warns.
Which products are affected?
Eight self-hosted products, and Atlassian says all versions before the fixed releases are vulnerable:
- Bitbucket Data Center
- Confluence Data Center
- Jira Software Data Center
- Jira Service Management Data Center
- Bamboo Data Center
- Crowd Data Center
- Crucible
- Fisheye
"All Data Center products listed below are at risk and require immediate attention," the advisory says.
Cloud customers are already covered. Atlassian says its affected Cloud products have been patched, its investigation found no evidence of exploitation, and no Cloud customer action is required.
Which versions fix it?
Atlassian recommends patching each affected installation to a fixed long-term support version or the latest release. The fixed versions listed in the advisory:
- Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1
- Confluence Data Center: 9.2.26, 10.2.19
- Jira Software Data Center: 9.12.40, 10.3.26, 11.3.12
- Jira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12
- Bamboo Data Center: 10.2.24, 12.1.12
- Crowd Data Center: 6.3.7, 7.0.3, 7.1.7, 7.2.4
- Crucible and Fisheye: 4.9.15
Atlassian no longer ships binary patches for flaws like this. Under its security bug fix policy, critical fixes are backported, and the company releases new maintenance versions instead.
What if you can't upgrade yet?
Get it off the internet. Atlassian's first temporary step is to remove the instance from the internet until you can patch or mitigate, if possible. "Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action," the advisory says.
That means a login page in front of the server is not enough protection here.
Atlassian then offers three mitigations:
- A web application firewall rule for all affected products. Admins add a regex to their firewall or proxy layer that blocks two dots placed directly next to a forward slash, a backslash or a double colon, including URL-encoded versions.
- A Tomcat RewriteValve rule for Confluence, Jira, Jira Service Management, Bamboo and Crowd. Admins back up the instance, enable the valve in the server configuration and add a rewrite rule that denies matching requests on every node.
- A urlrewrite.xml rule for Bitbucket only. It returns a 404 for matching requests and must be applied to every cluster node, mirror and mirror farm node.
The pattern being blocked is the classic sign of a path traversal attempt, where a request tries to climb out of one folder and into another.
Was anyone hacked?
That's unknown for self-hosted servers. "Atlassian cannot confirm if your instances have been affected by this vulnerability," the advisory says, and it tells customers to have their security teams check every affected instance for evidence of compromise.
Where to look: Atlassian says to URL-decode each access log request line, up to two decoding passes, and search for two dots directly next to a slash, a backslash or a double colon. Admins can also search the raw log lines with the same regex used in the firewall rule.
Atlassian didn't credit any researcher or organization with reporting the flaw in its advisory.
Why this one matters
Atlassian's self-hosted tools have been a favorite target before.
CISA's Known Exploited Vulnerabilities catalog, the US government's list of flaws attackers are known to have used, includes more than a dozen Atlassian bugs. Two of them look a lot like this one: CVE-2021-26085, a pre-authorization arbitrary file read in Confluence Server, and CVE-2021-26086, a path traversal flaw in Jira Server and Data Center.
The catalog also lists several Confluence Data Center and Server flaws from 2023, including CVE-2023-22515, CVE-2023-22518 and CVE-2023-22527.
None of that means CVE-2026-21589 is being exploited. But it explains why Atlassian is telling admins to take exposed servers offline rather than wait for a convenient window.
The cloud angle
The flaw lands in the middle of Atlassian's push to move everyone off self-hosted software.
In September 2025, Atlassian announced it was sunsetting its Data Center products. In its announcement, the company said 99% of its more than 300,000 customers already use its cloud platform.
The timeline Atlassian published:
- March 30, 2026: new customers can no longer buy Data Center subscriptions or Marketplace Data Center apps.
- March 30, 2028: last date for existing customers to buy new licenses, apps and expansions.
- March 28, 2029: end of life. Data Center subscriptions and associated Marketplace apps expire and become read-only.
Until that 2029 date, Atlassian says it will keep providing security bug fixes for critical vulnerabilities in Data Center products, which is exactly what this advisory is.
Not everything is going away. Atlassian says Bitbucket and Bamboo Data Center will not reach end of life. Existing customers get a Bitbucket Hybrid License covering Bitbucket Data Center, Bamboo Data Center and Bitbucket Cloud. Jira Align Data Center is also excluded.
Help with the move: in the same announcement, Atlassian said customers with fewer than 1,000 users get self-service upgrade tools. Organizations with more than 1,000 users can join a free FastShift Program, which Atlassian says cuts migration timelines from 12 to 16 months down to 2 to 6 months. Customers with over 5,000 users get a dedicated Solution Design Acceleration program.
For US government customers, Atlassian says it is building FedRAMP High and Impact Level 5 cloud environments to submit for authorization before Data Center reaches end of life.
The Register notes that customers who already moved to Atlassian's cloud have nothing to do this time, which "rather vindicates" Atlassian's earlier decisions to end its server products and then its Data Center line. It also notes Atlassian has admitted the migration hasn't been easy.
What it means for you
- If your company self-hosts Jira, Confluence, Bitbucket or another listed product: upgrade to a fixed version now. If you can't, restrict internet access and apply one of Atlassian's mitigations.
- If you're the security team: check access logs on every affected instance using Atlassian's patterns, and review what sensitive files sit in the web application root.
- If you're on Atlassian Cloud: nothing to do. Atlassian has already patched it.
- If you're planning a cloud move anyway: this is one more data point in that conversation, but don't let the migration debate delay the patch.
The bottom line
Atlassian disclosed a critical, no-login file access flaw across eight of its self-hosted Data Center products, including Jira, Confluence and Bitbucket. Fixed versions are available, cloud customers are already safe, and Atlassian says it can't tell whether self-hosted servers have been hit. Admins should patch, cut public access if they can't, and check their logs.
Key facts
- Vulnerability
- CVE-2026-21589, arbitrary file access
- Severity
- Critical, CVSS 9.3 (Atlassian's assessment)
- Login needed
- No
- Affected
- 8 Data Center products, all versions before the fixes
- Cloud customers
- Already patched, no action needed
- Advisory date
- October 5, 2026
Got questions?
Quick answers, plain wordsWhat is CVE-2026-21589?
An arbitrary file access vulnerability in Atlassian's self-hosted Data Center products. It lets an unauthenticated attacker access specific files within the web application root directory of an affected server.
How serious is it?
Atlassian rates it Critical, with a CVSS score of 9.3 under its own assessment. The company says all listed Data Center products are at risk and require immediate attention.
Which products are affected?
Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. All versions before the fixed releases are affected.
Can an attacker read any file on the server?
No. The flaw reaches files inside the web application root, and the attacker must already know the exact file name and path. It does not let anyone list the contents of a directory. But Atlassian warns some configurations hold sensitive files there.
Is it being exploited?
Atlassian says its investigation found no evidence of exploitation of its Cloud products. For Data Center, it says it cannot confirm whether customer instances have been affected and advises checking access logs.
Which versions fix it?
Bitbucket 9.4.26, 10.2.8 or 10.5.1; Confluence 9.2.26 or 10.2.19; Jira Software 9.12.40, 10.3.26 or 11.3.12; Jira Service Management 5.12.40, 10.3.26 or 11.3.12; Bamboo 10.2.24 or 12.1.12; Crowd 6.3.7, 7.0.3, 7.1.7 or 7.2.4; Crucible and Fisheye 4.9.15.
What if we can't patch right away?
Atlassian says to remove the instance from the internet if possible, including instances behind user logins. It also offers three mitigations: a web application firewall rule, a Tomcat RewriteValve rule for Confluence, Jira, Jira Service Management, Bamboo and Crowd, and a urlrewrite.xml rule for Bitbucket.
Do Atlassian Cloud customers need to do anything?
No. Atlassian says affected Cloud products have already been patched and no Cloud customer action is required.
How do I check whether my server was attacked?
Atlassian advises URL-decoding access log lines, up to two passes, and searching for two dots placed directly next to a slash, a backslash or a double colon. You can also search raw log lines with the regex pattern in the advisory.
Has Atlassian had flaws like this before?
Yes. CISA's Known Exploited Vulnerabilities catalog lists a 2021 pre-authorization arbitrary file read in Confluence Server, CVE-2021-26085, and a 2021 path traversal in Jira Server and Data Center, CVE-2021-26086, among other Atlassian bugs attackers have used.
SourcesAtlassian security advisory
Topics and tagsCybersecurity, Data centers, atlassian, jira
Related stories

Citrix rushes out patches for another NetScaler zero-day as attackers crash appliances
A new flaw in NetScaler's SAML login feature is being exploited to knock appliances offline, weeks after two other zero-days. Admins who just patched have to patch again.

Denmark's national ID register breached, exposing 8.8 million people's CPR numbers
Unknown attackers abused a private company's legal access to Denmark's Central Person Register to pull names, addresses and CPR numbers for about 8.8 million people.

A Pentagon records system was breached for 9 months before anyone noticed
The Defense Manpower Data Center disclosed that unauthorized users accessed unencrypted personal data on 2.76 million living and 294,000 deceased people between October 2025 and July 2026.
More in brief
- OpenAI apologizes to Australian lawmakers for its AI agent's Medicare website hackOct 6
- UK regulator Ofcom investigates Meta over Instagram's disappearing-photo feature InstantsOct 6
- South Korea's president says AI was likely used in a wave of bank hacksOct 6
- ChatGPT is signing fake New Yorker cartoons with real cartoonists' namesOct 6
- Schneider Electric agrees to buy PTC for $22.6 billion in its biggest deal everOct 6
- A researcher found the same AI agent flaw at Google, Rapid7 and more. He calls it 'protocol pivoting'Oct 5