TL;DR
Atlassian has patched CVE-2026-21589, a critical Atlassian Data Center vulnerability with a CVSS score of 9.3. The arbitrary file access bug lets an unauthenticated attacker read files from the web application root. It affects every version of eight self-managed products, including Jira, Confluence and Bitbucket.
- CVE: CVE-2026-21589
- CVSS: 9.3 (Critical · CVSSv4)
- Product: Atlassian Bamboo Data Center
- Affected: All other versions, All versions
- Status: No confirmed exploitation yet
- Patched in: Patch version 10.2.4 and later, Patch version 12.1.12 and later, Patch version 10.2.8 and later, Patch version 10.5.1 and later (+12 more)
- Action: Update to Patch version 10.2.4 and later, Patch version 12.1.12 and later, Patch version 10.2.8 and later, Patch version 10.5.1 and later (+12 more) now
Tired of noisy Atlassian CVE feeds? Set your own EPSS/CVSS alert threshold.
Try free for 14 daysWhy It Matters
Atlassian’s self-managed products sit at the heart of many development and IT teams. Source code, tickets, build pipelines and user directories often live on these servers. As a result, this Atlassian Data Center vulnerability touches a wide slice of the software supply chain. The single flaw hits eight products at once:
- Jira Data Center and Jira Service Management Data Center
- Confluence Data Center
- Bitbucket Data Center
- Bamboo Data Center
- Crowd Data Center
- Fisheye and Crucible
Cloud customers can relax. Atlassian says “affected Atlassian Cloud products have been patched, and our investigation has not found any evidence of exploitation.” The company also notes that Bitbucket Cloud is not affected. For self-managed instances, no exploitation in the wild or public proof-of-concept has been confirmed.
How the Attack Works
Atlassian classifies the bug as path traversal. It “allows an unauthenticated attacker to access specific files within the web application root directory,” the advisories state.
In practice, an attacker sends a crafted URL with directory traversal sequences. The server then returns a file it should have kept private. This arbitrary file access does not need a login or any user interaction.
However, the flaw has limits. “Exploitation requires prior knowledge of the target file’s exact name and path,” Atlassian explains. Attackers also cannot list directory contents. Even so, the company warns that “in some configurations, there may be sensitive files present that increase your risk.”
Affected Versions
All versions of each product are affected, including end-of-life releases. Atlassian lists these fixed versions:
- Jira Data Center: 9.12.40, 10.3.26 or 11.3.12
- Jira Service Management Data Center: 5.12.40, 10.3.26 or 11.3.12
- Confluence Data Center: 9.2.26 or 10.2.19
- Bitbucket Data Center: 9.4.26, 10.2.8 or 10.5.1
- Bamboo Data Center: 10.2.24 or 12.1.12
- Crowd Data Center: 6.3.7, 7.0.3, 7.1.7 or 7.2.4
- Fisheye and Crucible: 4.9.15
Disclosure Timeline
Atlassian opened the product tickets on October 2 and 3, 2026. It then published the advisories and fixes on October 5. The company has not said who reported the bug.
Patch and Mitigation Steps
Upgrade First
Upgrade to a fixed version as soon as possible. Each product has its own advisory: Jira Data Center, Confluence Data Center, Bitbucket Data Center, Bamboo Data Center, Crowd Data Center, Fisheye and Crucible.
Temporary Mitigations
Teams that cannot patch right away should pull exposed instances off the internet. Next, add Atlassian’s web application firewall rule to block path traversal sequences. Jira, Confluence, Bamboo and Crowd can also block these requests through Tomcat’s RewriteValve. Bitbucket uses a rule in urlrewrite.xml instead.
Atlassian stresses that these steps are “not a replacement for patching.” Therefore, treat this Atlassian Data Center vulnerability as an urgent upgrade, especially for internet-facing servers.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!