SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

Atlassian has disclosed CVE-2026-21589, a critical unauthenticated arbitrary file access flaw affecting Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye Data Center products. Attackers need the exact file path; directory listing is not possible. Cloud is already patched. This article covers impact, fixed versions, and temporary mitigations.

Oct 8, 2026By Bapanapalli Prem Sai Siddhik
vulnerability research

Summary

Atlassian has published a security advisory for CVE-2026-21589, a critical arbitrary file access vulnerability affecting multiple Data Center and related products. An unauthenticated attacker can access specific files within the web application root directory when the exact file name and path are known. The flaw does not allow directory listing or enumeration. Atlassian rates the issue Critical and recommends immediate patching. Affected Atlassian Cloud products have been patched; no Cloud customer action is required. Atlassian’s investigation has not found evidence of exploitation against Cloud.

Full product guidance is in the official Atlassian advisory.

Vulnerability Details

CVE ID CVSS Score EPSS Score Type
CVE-2026-21589 9.3 1.755% CWE-552: Files or Directories Accessible to External Parties

Technical Information

Critical Unauthenticated No User Interaction Arbitrary File Access Public PoC

CVE-2026-21589 — Arbitrary File Access in Multiple Atlassian Products

The vulnerability allows access to specific files inside the web application root directory of affected self-managed products. A remote attacker does not need credentials. Successful use of the issue depends on already knowing the exact name and path of the target file. The flaw does not provide a way to list or enumerate directory contents, so guessing or discovering paths through the vulnerability itself is outside the published attack model.

Access is limited to the web application root, not the wider host filesystem. Within that root, some deployments may hold sensitive material (for example configuration under known application paths). Atlassian notes that those layouts increase risk when the exact path is known to an attacker.

Temporary controls in the advisory focus on blocking request patterns where .. appears immediately next to /, \, or ::, including URL-encoded forms of those separators. That guidance applies across the affected product set via WAF or proxy rules, with product-specific Tomcat RewriteValve or Bitbucket urlrewrite.xml options where patching cannot be applied at once.

All versions of the listed Data Center and related products prior to the fixed releases are affected. Atlassian recommends moving to a fixed LTS version or later. Affected Atlassian Cloud products have already been patched; no Cloud customer action is required. Atlassian’s investigation has not found evidence of exploitation against Cloud. For self-managed instances, Atlassian states it cannot confirm whether systems have been affected and advises local security review of access logs.

Proof of Concept Analysis

A public detection artifact for CVE-2026-21589 has been published. It demonstrates how an unauthenticated client can probe Jira, Confluence, and Bitbucket instances for responses consistent with arbitrary file access under the web application root when a known path is used.

The exploitation flow can be understood in the following high-level stages:

1. Target Identification

The attacker first identifies an internet-reachable self-managed instance of an affected product. No authentication is required. The goal is a host that still serves product download or static-resource style endpoints used by the application.

2. Path Manipulation

The core of the issue is how certain resource paths are resolved. A request is built so that path elements place .. immediately next to /, \, or :: (including URL-encoded forms). That is the same class of pattern Atlassian’s temporary mitigations are intended to block.

3. Triggering the Vulnerability

The crafted request is sent without credentials. On an affected build, path handling can resolve to a concrete file under the web application root when the exact relative path is already known. The vulnerability does not list directories; the file name and path must be correct for the read to succeed.

4. Impact on the Target

If the target file exists at that path, its contents can be returned in the HTTP response. Typical verification targets are standard files under the application root (for example under WEB-INF). Access is limited to that root, not the wider host filesystem. Sensitive configuration present under known paths increases risk.

5. Verification

Successful triggering is observed when file content is returned for a known path. Patched instances or correctly applied temporary request filters do not return that content. Public detectors send product-specific probes for Jira, Confluence, and Bitbucket and report whether the response matches a vulnerable pattern.

The existence of a public detector increases the risk of automated scanning against unpatched, internet-facing instances.

Exploitation Flow (High-Level)

STEP 1
Target
Identification
→
STEP 2
Path
Manipulation
→
STEP 3
Triggering the
Vulnerability
→
STEP 4
Impact on
the Target
→
STEP 5
Verification

No authentication is required. Success depends on a known file path under the web application root; the issue does not enumerate directories.

Impact

  • Unauthorized file access
    A remote attacker without authentication can read specific files under the web application root when the path is known, which may expose configuration or other sensitive material depending on deployment layout.

Affected Products

The following products are affected in all versions prior to the fixed releases:

  • Bitbucket Data Center
  • Confluence Data Center
  • Jira Service Management Data Center
  • Jira Software Data Center
  • Bamboo Data Center
  • Crowd Data Center
  • Crucible
  • Fisheye

MITRE ATT&CK Mapping

Technique ID Technique Name Tactic ID Tactic
T1190 Exploit Public-Facing Application TA0001 Initial Access
T1005 Data from Local System TA0007 Discovery

Mitigation and Recommendations

Atlassian recommends patching each affected installation to a fixed version or the latest version as soon as possible.

Fixed Versions

Product Fixed Versions
Bitbucket Data Center 9.4.26, 10.2.8, 10.5.1
Confluence Data Center 9.2.26, 10.2.19
Jira Service Management Data Center 5.12.40, 10.3.26, 11.3.12
Jira Software Data Center 9.12.40, 10.3.26, 11.3.12
Bamboo Data Center 10.2.24, 12.1.12
Crowd Data Center 6.3.7, 7.0.3, 7.1.7, 7.2.4
Crucible 4.9.15
Fisheye 4.9.15

Temporary mitigations

If immediate patching is not possible, Atlassian recommends removing internet exposure until a fixed build or temporary control is in place. Instances reachable from the public internet, including those that require user authentication, should be restricted from external network access where feasible.

Additional temporary options in the advisory include:

  • A web application firewall or proxy rule that blocks URLs containing .. immediately adjacent to /, \, or ::, including URL-encoded forms
  • Tomcat RewriteValve rules for Confluence, Jira Service Management, Jira Software, Bamboo, and Crowd
  • A urlrewrite.xml rule for Bitbucket Data Center (including mirrors and mirror farm nodes)

Exact rule text and product-specific paths are in the official advisory. Back up configurations before applying temporary changes, and restart affected nodes as required.

Recommended Actions

  • Upgrade each affected product to a fixed version listed above, or to a later supported release.
  • Prefer the fixed LTS line where Atlassian recommends it for your product.
  • If you cannot patch immediately, restrict external access and apply the temporary WAF, RewriteValve, or Bitbucket rewrite controls from the advisory.
  • Engage your security team to review access logs for evidence of compromise. Atlassian notes it cannot confirm whether self-managed instances have been affected; decode access-log request lines and search for .. adjacent to /, \, or ::, or use the advisory regex on raw log lines.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated solution that helps you quickly remediate risks, including critical third-party application updates. It supports Windows, Linux, macOS, and 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Critical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality
vulnerability researchCritical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality

CVE Research

Critical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality

SonicWall has disclosed CVE-2026-102255, a critical pre-authentication SSRF vulnerability in SMA 1000 Work Place that can let unauthenticated attackers reach internal functionality and perform unauthorized operations. The advisory also covers three additional SMA 1000 issues. Fixed platform-hotfixes are available; SonicWall reports no evidence of in-the-wild exploitation at publication.

Oct 8, 2026

Open New NetScaler SAML Zero-Day Exploited in Targeted Attacks, Causes Denial of Service
vulnerability researchNew NetScaler SAML Zero-Day Exploited in Targeted Attacks, Causes Denial of Service

CVE Research

New NetScaler SAML Zero-Day Exploited in Targeted Attacks, Causes Denial of Service

Citrix has disclosed CVE-2026-88779, a high-severity memory overflow in NetScaler ADC and NetScaler Gateway that can cause denial of service when the appliance is configured as a SAML service provider or identity provider. Targeted attacks on unmitigated deployments have been observed. This article covers impact, affected versions, configuration checks, temporary Global Deny List guidance, and fixed builds.

Oct 8, 2026

Open Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

CVE Research

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Oct 5, 2026

Open CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability
CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

CVE Research

CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

Oct 5, 2026