Atlassian Discloses Critical Pre-Auth File-Access Flaw Across Eight Data Center Products
Atlassian has published a security advisory warning customers of a critical arbitrary file-access vulnerability, tracked as CVE-2026-21589, affecting multiple self-hosted Data Center products. The flaw, disclosed October 5, 2026, lets an unauthenticated attacker retrieve specific files from within the web application root directory of vulnerable servers — no login, session, or user interaction required. Atlassian rates the issue 9.3 (Critical) on the CVSS 4.0 scale, with the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H.
The advisory covers eight products: Jira Software Data Center, Jira Service Management Data Center, Confluence Data Center, Bitbucket Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian says every version prior to the fixed releases is affected, including versions that are already past end-of-life. Atlassian Cloud products were patched automatically ahead of the public disclosure, and Atlassian states its investigation found no evidence of exploitation on Cloud. Bitbucket Cloud is not affected by this issue at all.
As of the advisory date, Atlassian reports no evidence of in-the-wild exploitation and no public proof-of-concept exploit has been confirmed for self-managed instances. Given the pre-authentication nature of the bug and the ubiquity of these products inside enterprise networks, researchers are urging administrators not to wait for an active-exploitation signal before patching.
Vulnerability Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-21589 |
| Vulnerability Class | Path traversal → arbitrary file access |
| CVSS Score | 9.3 (Critical), CVSS 4.0 |
| CVSS Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H |
| Authentication Required | None (pre-auth) |
| Disclosed By | Atlassian (self-reported, internal discovery) |
| Advisory Date | October 5, 2026 |
| Affected Products | Jira Software DC, Jira Service Management DC, Confluence DC, Bitbucket DC, Bamboo DC, Crowd DC, Crucible, Fisheye |
| Not Affected | Atlassian Cloud (pre-patched), Bitbucket Cloud |
| Exploitation Status | No evidence of active exploitation or public PoC as of October 6, 2026 |
How the Flaw Works
Path Traversal Into the Web Root
CVE-2026-21589 is a classic path traversal weakness. An attacker sends a specially crafted URL containing an encoded .. sequence, stepping the request outside the directory the application intends to serve. The server then returns the contents of a file located within the web application root directory, without requiring a login.
Built-In Limits — But Real Risk
Atlassian notes two mitigating constraints: the attacker must already know the exact file name and path they want to retrieve, and the vulnerability cannot be used to enumerate or list directory contents. In other words, this is not a browsable file-disclosure bug — it is a targeted read primitive. Atlassian cautions, however, that some deployment configurations leave sensitive files inside that directory tree, without specifying exactly which files or setups raise the risk, meaning the real-world severity depends heavily on how a given instance was installed and configured.
Fixed Versions by Product
| Product | Fixed Versions |
|---|---|
| Jira Software Data Center | 9.12.40, 10.3.26, 11.3.12 |
| Jira Service Management Data Center | 5.12.40, 10.3.26, 11.3.12 |
| Confluence Data Center | 9.2.26, 10.2.19 |
| Bitbucket Data Center | 9.4.26, 10.2.8, 10.5.1 |
| Bamboo Data Center | 10.2.24, 12.1.12 |
| Crowd Data Center | 6.3.7, 7.0.3, 7.1.7, 7.2.4 |
| Crucible | 4.9.15 |
| Fisheye | 4.9.15 |
Admins running any version prior to these fixed releases — including unsupported, end-of-life builds — are vulnerable and should treat patching as mandatory rather than best-effort.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | Unauthenticated read access to files in the web application root; scope of exposure depends on what sensitive material (config files, keys, tokens) sits in that directory on a given install |
| Scope of Affected Estate | Eight separate Data Center / server products, spanning issue tracking, wikis, source control, CI/CD, identity (Crowd), and legacy code-review tools (Crucible, Fisheye) |
| End-of-Life Exposure | Organizations still running unsupported versions of any affected product get no official fix path other than upgrading to a currently supported, patched release |
| Attack Complexity | Low — no credentials, no user interaction, and the request itself is a standard HTTP call with an encoded traversal sequence |
| Detection Difficulty | Moderate — exploitation leaves traversal patterns in access logs, but requires admins to actively look rather than wait for an alert |
| Cluster-Wide Exposure | Mitigations must be applied to every node in a clustered deployment (including Bitbucket mirror and mirror-farm nodes), not just the primary instance |
Recommendations
For Atlassian Data Center Administrators
- Patch immediately to the fixed version listed above for each affected product. This is the only complete remediation.
- If immediate patching is not possible, restrict external network access to the affected instance, including for internet-facing deployments that normally require authentication — the vulnerability bypasses authentication entirely.
- Apply a web application firewall (WAF) or reverse-proxy rule blocking URL requests containing encoded traversal sequences (
..and its common encodings) as a temporary compensating control. - For Confluence, Jira Software, Jira Service Management, Bamboo, and Crowd, Atlassian's advisory documents a Tomcat RewriteValve configuration that can block exploitation attempts at the application server layer.
- For Bitbucket, apply the documented
urlrewrite.xmlrule change rather than the Tomcat RewriteValve approach. - Apply any temporary mitigation consistently across every cluster node — a single unpatched or unmitigated node (including Bitbucket mirror farm nodes) leaves the whole deployment exposed.
- If running Crucible or Fisheye, note these are legacy products with a single fixed version (4.9.15); confirm whether your organization still has vendor support before planning the upgrade path.
For Security Teams / Incident Responders
- Review web server and application access logs for requests containing encoded path-traversal patterns (
%2e%2e, double-encoded variants, and similar) against affected product endpoints, going back to well before the October 5 disclosure date. - Treat any instance that was internet-facing and unpatched between the vulnerable release and the applied fix as a candidate for deeper investigation, not just a patch target.
- Inventory every self-hosted Atlassian Data Center product in your environment against the fixed-version table above — a single overlooked Crowd or Bamboo instance tied into the same identity or build infrastructure can undercut remediation elsewhere.
- Confirm Cloud-hosted instances require no action, but verify via your Atlassian admin console that any hybrid deployments (Cloud plus self-hosted) don't have an overlooked Data Center component.
For End Users
- No end-user action is required; this is an infrastructure-level vulnerability that administrators must remediate.
- If your organization notifies you of remediation on a shared Jira, Confluence, or Bitbucket instance, follow any password-reset or re-authentication guidance issued, out of general caution, even though this specific flaw does not directly expose credentials by itself.
Key Takeaways
- CVE-2026-21589 is a pre-auth, CVSS 9.3 path traversal flaw affecting eight Atlassian Data Center / server products — Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye.
- Every version before the fixed releases is vulnerable, including end-of-life builds with no other official remediation path.
- Exploitation requires prior knowledge of an exact file path and cannot enumerate directories — but Atlassian warns some configurations expose sensitive files within reach regardless.
- Atlassian Cloud and Bitbucket Cloud are not affected; cloud customers need take no action.
- No active exploitation or public proof-of-concept has been confirmed as of October 6, 2026, but the pre-authentication, low-complexity nature of the bug makes rapid weaponization plausible.
- Mitigations and patches must be applied to every cluster node, including Bitbucket mirror farms — a single unmitigated node undermines the rest of the deployment.