Atlassian Warns of Critical CVE-2026-21589 File Access Flaw in Jira, Confluence and Bitbucket
Atlassian is warning customers about a critical vulnerability tracked as CVE-2026-21589. The flaw enables arbitrary file access in multiple self-hosted Data Center products, including Confluence, Jira and Bitbucket.
An unauthenticated attacker could exploit the vulnerability to access certain files in the web root directory of an affected application. However, exploitation requires prior knowledge of the exact name and path of the targeted file.
What is CVE-2026-21589?
Atlassian describes CVE-2026-21589 as an arbitrary file access vulnerability affecting multiple products:
“This arbitrary file access vulnerability allows an unauthenticated attacker to access certain files in the root directory of an affected version of a web application,” Atlassian said in its security advisory.
Atlassian said the vulnerability does not allow attackers to enumerate or list directory contents:
“Exploitation requires prior knowledge of the exact name and path of the target file; this vulnerability does not allow an attacker to enumerate or list the contents of a directory.”
Atlassian products affected by the vulnerability
CVE-2026-21589 affects product versions released before the following fixed versions:
- Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1
- Confluence Data Center: 9.2.26, 10.2.19
- Jira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12
- Jira Software Data Center: 9.12.40, 10.3.26, 11.3.12
- Bamboo Data Center: 10.2.24, 12.1.12
- Cloud Data Center: 6.3.7, 7.0.3, 7.1.7, 7.2.4
- Crucible: 4.9.15
- Fisheye: 4.9.15
Atlassian urges immediate patching
Atlassian recommends that system administrators managing self-hosted instances apply the available security updates immediately. Cloud customers do not need to take action because the vendor automatically patches its cloud products.
If an update cannot be applied immediately, Atlassian recommends restricting access from external networks, including internet-facing instances that require user authentication.
Temporary mitigations for CVE-2026-21589
Temporary mitigation options include adding web application firewall (WAF) or proxy rules to block the specified traversal pattern across affected products.
Administrators can also use Tomcat RewriteValve rules for Confluence, Jira Service Management, Jira, Bamboo and Crowd, or URL rewrite rules for Bitbucket. Atlassian’s advisory includes step-by-step instructions and configuration details for implementing these mitigations.
Any mitigation changes must be applied across all cluster nodes, including Bitbucket mirrors and mirror farm nodes.
No evidence of active exploitation
Atlassian said there is currently no evidence that CVE-2026-21589 is being exploited in attacks. However, the company is urging administrators to review access logs for the traversal patterns listed in its security bulletin.
The vendor said it could not determine whether individual customer instances had been compromised. Organizations using self-hosted instances should work with their local security teams to investigate potential exposure.
Join Mikko Hypponen and security leaders from the NFL, Chanel and Atlassian for a two-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix and revalidate at machine speed.
Source: www.bleepingcomputer.com



