Atlassian Data Centre products hit by unauthenticated file access vulnerability

Key points

Atlassian has fixed CVE-2026-21589, a critical flaw rated 9.3 on the CVSS 4.

Atlassian Data Centre products hit by unauthenticated file access vulnerability

Atlassian Data Centre products hit by unauthenticated file access vulnerability

Key points

  • Atlassian has fixed CVE-2026-21589, a critical flaw rated 9.3 on the CVSS 4.0 scale that lets unauthenticated attackers read files from the web application root of eight self-hosted products, including Bitbucket, Confluence, Jira Software and Bamboo.
  • Cloud customers need take no action, as Atlassian has patched affected Cloud products and found no evidence of exploitation there, while self-hosted users should upgrade to fixed releases such as Confluence 9.2.26 or 10.2.19 and Jira Software 9.12.40, 10.3.26 or 11.3.12.
  • Where patching isn’t immediately possible, Atlassian recommends taking internet-facing instances offline or applying a web application firewall rule, a Tomcat RewriteValve configuration, or a urlrewrite.xml rule for Bitbucket to block directory traversal attempts.




Atlassian Data Centre products hit by unauthenticated file access vulnerability








Collaboration vendor Atlassian has released fixes for a critical vulnerability that lets unauthenticated attackers read files from the web application root of eight of its self-hosted products.

The flaw is tracked as CVE-2026-21589 and affects Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd Data Center, along with the Crucible and Fisheye code review tools.

In its advisory Atlassian said every version prior to the fixed releases was vulnerable.

The company rated the bug 9.3 out of 10.0 on the CVSS 4.0 scale, while noting this was its own internal assessment and that customers should judge how it applied to their environments.

Attackers face one hurdle, as exploitation requires knowing the exact name and path of the target file, and the flaw cannot be used to list directory contents.

Nevertheless, Atlassian products install to well-documented default locations.

Atlassian itself warned that some configurations could leave sensitive files exposed, raising the risk.

No action is required by Cloud customers with Atlassian saying it had patched affected Cloud products and found no evidence of exploitation there.

Fixed releases include Confluence 9.2.26 and 10.2.19, Jira Software 9.12.40, 10.3.26 and 11.3.12, and Bitbucket 9.4.26, 10.2.8 and 10.5.1.

For those unable to patch immediately, Atlassian’s first recommendation is to take internet-facing instances offline, including those protected by user authentication.

Failing that, it offered three stopgaps: a web application firewall rule, a Tomcat RewriteValve configuration, or for Bitbucket, a rule added to its urlrewrite.xml file.

All three block requests containing two dots next to a path separator, the signature of directory traversal, where an attacker uses “../” sequences to climb out of the folder a web server is meant to serve.

Security teams were also told to search access logs for the same pattern, decoding each request line up to twice beforehand, since attackers routinely double-encode characters to slip past filters.

The disclosure adds to a chequered record for Atlassian’s self-hosted software, with Confluence flaws CVE-2022-26134 and CVE-2023-22515 both exploited in the wild soon after they surfaced.



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.