Atlassian warned on 6 October 2026 that CVE-2026-21589 lets an unauthenticated attacker read specific files from the web root of eight self-hosted products. The company scores it 9.3 under CVSS 4.0. Atlassian Cloud is already patched. Self-hosted Data Center is not.
What happened
This is arbitrary file access, not a directory listing. The attacker must already know the exact file name and path. That limit matters, but it does not make the bug safe. Atlassian says some configurations leave sensitive files in that directory, and those cases are highly severe.
The vulnerable code has been present for years, back to Jira Software 7.1.0, Confluence 5.10.0, and Bitbucket 4.6.0, among others. Atlassian says it has no evidence of exploitation so far, and it cannot tell from its side whether a customer instance was hit. Administrators should still review access logs for the traversal patterns in the bulletin.
Who is affected
Every self-hosted version before the fixed releases is vulnerable, including builds past end of life. Cloud customers do not need to act. Fixed releases are Bitbucket Data Center 9.4.26, 10.2.8 and 10.5.1; Confluence Data Center 9.2.26 and 10.2.19; Jira Software Data Center 9.12.40, 10.3.26 and 11.3.12; Jira Service Management Data Center 5.12.40, 10.3.26 and 11.3.12; Bamboo Data Center 10.2.24 and 12.1.12; Crowd Data Center 6.3.7, 7.0.3, 7.1.7 and 7.2.4; Crucible 4.9.15; Fisheye 4.9.15.
What to do now
- Patch self-hosted Data Center now if the instance is reachable from the internet, even when a login is required.
- Apply the fix on every node, including Bitbucket mirrors and mirror-farm nodes.
- If you cannot patch today, restrict external network access. Atlassian also documents WAF or proxy rules, Tomcat RewriteValve rules, and a Bitbucket URL rewrite as temporary controls.
- Search access logs for the traversal patterns in the advisory before you assume the box was only probed.
Source: BleepingComputer, citing Atlassian's security advisory. Atlassian warns of critical file-access flaw in Jira, Confluence.
Also on the blog
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- Ninja Forms CVE-2026-94504 exploited on a plugin used by 500,000 sites
- Fake ChatGPT and Gemini ad portals steal Google and Okta MFA codes
- Nikkei Microsoft 365 account sent 9,000 phishing emails after takeover
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.