Atlassian CVE-2026-21589: A 9.3 File-Access Flaw Hits Every Data Center Version of Eight Products
Security / news
Atlassian CVE-2026-21589: A 9.3 File-Access Flaw Hits Every Data Center Version of Eight Products
An unauthenticated request can read a file from the web root if the attacker already knows its exact path. Atlassian reports no exploitation and has released fixes for each product line.

An unauthenticated attacker can read specific files from the web application root of any self-hosted Atlassian Data Center product, provided the attacker already knows the file's exact name and path. Atlassian rates the flaw (CVE-2026-21589) 9.3 and published fixes on Monday, October 5, 2026. It reports no evidence of exploitation so far.
The Confluence tracker entry for the issue classifies it as path traversal and says all Confluence Data Center versions are affected. Help Net Security lists the full set: Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd Data Center, plus Crucible and Fisheye.
What an attacker can and cannot do
Atlassian's wording, quoted by BleepingComputer, is that "exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents."
That precondition narrows the practical risk below what a 9.3 suggests, but it does not remove it, because the attacker needs no credentials. The score reflects unauthenticated file reads. None of the reports describe code execution or write access.
The breadth is the story. Eight products share the flaw, and the table below lists 18 fixed version numbers across them, so an organisation running Jira, Confluence and Bitbucket side by side has three upgrades to schedule, not one. Help Net Security gives October 5 as the publication date.
Atlassian says its cloud products are already patched, found no evidence of exploitation there, and that cloud customers need to do nothing.
Fixed versions
| Product | Fixed in |
|---|---|
| Bitbucket Data Center | 9.4.26, 10.2.8, 10.5.1 |
| Confluence Data Center | 9.2.26, 10.2.19 |
| Jira Software Data Center | 9.12.40, 10.3.26, 11.3.12 |
| Jira Service Management Data Center | 5.12.40, 10.3.26, 11.3.12 |
| Bamboo Data Center | 10.2.24, 12.1.12 |
| Crowd Data Center | 6.3.7, 7.0.3, 7.1.7, 7.2.4 |
| Crucible and Fisheye | 4.9.15 |
The two write-ups disagree slightly on Jira Service Management. BleepingComputer groups it with Jira Software under 9.12.40, while Help Net Security lists 5.12.40. Check Atlassian's bulletin for your exact version line before upgrading.
Mitigations if you cannot upgrade today
Atlassian's Confluence entry gives two temporary options. The first is a web application firewall rule that blocks path traversal patterns, using a regular expression the advisory supplies. The second is to configure Tomcat's RewriteValve in server.xml and apply the advisory's rewrite.config on every cluster node.
Both are stopgaps. Help Net Security reports that Atlassian also recommends taking affected internet-facing instances offline until updates are applied, and BleepingComputer advises reviewing access logs for traversal attempts.

Where this sits among recent patches
The site has covered other self-hosted products this month, including WordPress CVE-2026-87902 and the Zammad flaws now on CISA's exploited list. The Atlassian bulletin differs in one respect: it carries no exploitation report yet.
The next concrete marker is the first report of exploitation. Until then, self-hosted administrators should move to the fixed versions in the table, and anyone who cannot should apply the WAF rule or the Tomcat rewrite today.
Sources
More in Security
- 01Pwn2Own Ireland 2026 Day One: Seven of 20 Listed Entries Were Collisions, and OpenAI Codex Fell to Argument InjectionSamsung's Galaxy S26 was hit three times, Sonos and Philips Hue each twice or more, and a Google Pixel 10 attempt ran out of time. Vendors get 90 days before details go public.
- 02WordPress CVE-2026-87902: A Page-Template Bug in Every Release Since 4.7, Patched in 7.1.2The 9.2 rating describes a file include; code execution needs a theme folder starting with page- and a PHP setting, but probes began five hours after the patch.
- 03Citrix's September 27 NetScaler Fix Does Not Cover CVE-2026-88779, Now on CISA's Exploited ListBuilds that closed two exploited zero-days stay vulnerable to a SAML flaw that CISA added on October 4 with a three-day deadline.
- 04FortiMail CVE-2026-104286: Exploited 9.8 Flaw Lets Unauthenticated Requests Write FilesFortinet's advisory lists a workaround and fixed builds for three release branches; the 7.2 branch gets none.