Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products
Atlassian has disclosed CVE-2026-21589, a critical unauthenticated arbitrary file access flaw affecting Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye Data Center products. Attackers need the exact file path; directory listing is not possible. Cloud is already patched. This article covers impact, fixed versions, and temporary mitigations.
Summary
Atlassian has published a security advisory for CVE-2026-21589, a critical arbitrary file access vulnerability affecting multiple Data Center and related products. An unauthenticated attacker can access specific files within the web application root directory when the exact file name and path are known. The flaw does not allow directory listing or enumeration. Atlassian rates the issue Critical and recommends immediate patching. Affected Atlassian Cloud products have been patched; no Cloud customer action is required. Atlassian’s investigation has not found evidence of exploitation against Cloud.
Full product guidance is in the official Atlassian advisory.
Vulnerability Details
| CVE ID | CVSS Score | EPSS Score | Type |
|---|---|---|---|
| CVE-2026-21589 | 9.3 | 1.755% | CWE-552: Files or Directories Accessible to External Parties |
Technical Information
CVE-2026-21589 — Arbitrary File Access in Multiple Atlassian Products
The vulnerability allows access to specific files inside the web application root directory of affected self-managed products. A remote attacker does not need credentials. Successful use of the issue depends on already knowing the exact name and path of the target file. The flaw does not provide a way to list or enumerate directory contents, so guessing or discovering paths through the vulnerability itself is outside the published attack model.
Access is limited to the web application root, not the wider host filesystem. Within that root, some deployments may hold sensitive material (for example configuration under known application paths). Atlassian notes that those layouts increase risk when the exact path is known to an attacker.
Temporary controls in the advisory focus on blocking request patterns where .. appears immediately next to /, \, or ::, including URL-encoded forms of those separators. That guidance applies across the affected product set via WAF or proxy rules, with product-specific Tomcat RewriteValve or Bitbucket urlrewrite.xml options where patching cannot be applied at once.
All versions of the listed Data Center and related products prior to the fixed releases are affected. Atlassian recommends moving to a fixed LTS version or later. Affected Atlassian Cloud products have already been patched; no Cloud customer action is required. Atlassian’s investigation has not found evidence of exploitation against Cloud. For self-managed instances, Atlassian states it cannot confirm whether systems have been affected and advises local security review of access logs.
Proof of Concept Analysis
A public detection artifact for CVE-2026-21589 has been published. It demonstrates how an unauthenticated client can probe Jira, Confluence, and Bitbucket instances for responses consistent with arbitrary file access under the web application root when a known path is used.
The exploitation flow can be understood in the following high-level stages:
1. Target Identification
The attacker first identifies an internet-reachable self-managed instance of an affected product. No authentication is required. The goal is a host that still serves product download or static-resource style endpoints used by the application.
2. Path Manipulation
The core of the issue is how certain resource paths are resolved. A request is built so that path elements place .. immediately next to /, \, or :: (including URL-encoded forms). That is the same class of pattern Atlassian’s temporary mitigations are intended to block.
3. Triggering the Vulnerability
The crafted request is sent without credentials. On an affected build, path handling can resolve to a concrete file under the web application root when the exact relative path is already known. The vulnerability does not list directories; the file name and path must be correct for the read to succeed.
4. Impact on the Target
If the target file exists at that path, its contents can be returned in the HTTP response. Typical verification targets are standard files under the application root (for example under WEB-INF). Access is limited to that root, not the wider host filesystem. Sensitive configuration present under known paths increases risk.
5. Verification
Successful triggering is observed when file content is returned for a known path. Patched instances or correctly applied temporary request filters do not return that content. Public detectors send product-specific probes for Jira, Confluence, and Bitbucket and report whether the response matches a vulnerable pattern.
The existence of a public detector increases the risk of automated scanning against unpatched, internet-facing instances.
Exploitation Flow (High-Level)
Identification
Manipulation
Vulnerability
the Target
No authentication is required. Success depends on a known file path under the web application root; the issue does not enumerate directories.
Impact
-
Unauthorized file accessA remote attacker without authentication can read specific files under the web application root when the path is known, which may expose configuration or other sensitive material depending on deployment layout.
Affected Products
The following products are affected in all versions prior to the fixed releases:
- Bitbucket Data Center
- Confluence Data Center
- Jira Service Management Data Center
- Jira Software Data Center
- Bamboo Data Center
- Crowd Data Center
- Crucible
- Fisheye
MITRE ATT&CK Mapping
| Technique ID | Technique Name | Tactic ID | Tactic |
|---|---|---|---|
| T1190 | Exploit Public-Facing Application | TA0001 | Initial Access |
| T1005 | Data from Local System | TA0007 | Discovery |
Mitigation and Recommendations
Atlassian recommends patching each affected installation to a fixed version or the latest version as soon as possible.
Fixed Versions
| Product | Fixed Versions |
|---|---|
| Bitbucket Data Center | 9.4.26, 10.2.8, 10.5.1 |
| Confluence Data Center | 9.2.26, 10.2.19 |
| Jira Service Management Data Center | 5.12.40, 10.3.26, 11.3.12 |
| Jira Software Data Center | 9.12.40, 10.3.26, 11.3.12 |
| Bamboo Data Center | 10.2.24, 12.1.12 |
| Crowd Data Center | 6.3.7, 7.0.3, 7.1.7, 7.2.4 |
| Crucible | 4.9.15 |
| Fisheye | 4.9.15 |
Temporary mitigations
If immediate patching is not possible, Atlassian recommends removing internet exposure until a fixed build or temporary control is in place. Instances reachable from the public internet, including those that require user authentication, should be restricted from external network access where feasible.
Additional temporary options in the advisory include:
- A web application firewall or proxy rule that blocks URLs containing
..immediately adjacent to/,\, or::, including URL-encoded forms - Tomcat RewriteValve rules for Confluence, Jira Service Management, Jira Software, Bamboo, and Crowd
- A
urlrewrite.xmlrule for Bitbucket Data Center (including mirrors and mirror farm nodes)
Exact rule text and product-specific paths are in the official advisory. Back up configurations before applying temporary changes, and restart affected nodes as required.
Recommended Actions
- Upgrade each affected product to a fixed version listed above, or to a later supported release.
- Prefer the fixed LTS line where Atlassian recommends it for your product.
- If you cannot patch immediately, restrict external access and apply the temporary WAF, RewriteValve, or Bitbucket rewrite controls from the advisory.
- Engage your security team to review access logs for evidence of compromise. Atlassian notes it cannot confirm whether self-managed instances have been affected; decode access-log request lines and search for
..adjacent to/,\, or::, or use the advisory regex on raw log lines.
Instantly Fix Risks with Saner Patch Management
Saner patch management is a continuous, automated, and integrated solution that helps you quickly remediate risks, including critical third-party application updates. It supports Windows, Linux, macOS, and 550+ third-party applications.
It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.
Experience the fastest and most accurate patching software here.




