Atlassian patches critical file-read flaw CVE-2026-21589
CVE-2026-21589 lets unauthenticated attackers read files from eight Atlassian Data Center products. CVSS 9.3. Patch now; cloud instances are not affected.
Atlassian has patched CVE-2026-21589, an arbitrary file-access flaw it scores 9.3 that lets an unauthenticated attacker read files from the web application root of eight Data Center and Server products. The fix shipped in Atlassian's security bulletin on October 5. If you run any of these on-prem, patch now.
What the bug does
Per Atlassian, the flaw permits an attacker with no login credentials to read specific files inside each product's web application root directory, provided they know the exact path and filename. It is a path-traversal-class read primitive, not code execution — but config files, secrets left in the web root, and other readable artifacts are exactly where an attacker starts. The NVD entry tracks the record.
Cloud is not affected. Atlassian said it has "not found evidence of exploitation" in cloud products and that the flaw is addressed there, but added it "cannot confirm if your instances have been affected" for self-hosted deployments.
Affected versions
Fixed in the following releases (upgrade to the listed version or later in each supported line):
- Bitbucket Data Center — 9.4.26, 10.2.8, 10.5.1
- Confluence Data Center — 9.2.26, 10.2.19
- Jira Software Data Center — 9.12.40, 10.3.26, 11.3.12
- Jira Service Management Data Center — 5.12.40, 10.3.26, 11.3.12
- Bamboo Data Center — 10.2.24, 12.1.12
- Crowd Data Center — 6.3.7, 7.0.3, 7.1.7, 7.2.4
- Crucible — 4.9.15
- Fisheye — 4.9.15
Exploitation status
No public exploitation has been reported, and no PoC is public at time of writing. Atlassian's advisory is the only authority on scope so far; treat the absence of an exploited-in-the-wild tag as "not yet seen," not "safe." A pre-auth read primitive across this many high-value internal services is the kind of bug that attracts scanning fast.
Action checklist
- Inventory every on-prem Bitbucket, Confluence, Jira, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye instance. Data Center and Server only — Atlassian Cloud is out of scope.
- Upgrade to the fixed version for your product line (list above).
- Rotate any secrets, tokens, or credentials that may have been readable from the web application root while unpatched.
- Review access logs for unauthenticated requests to unusual file paths on the affected hostnames.
Context
Atlassian's advisory bundles CVE-2026-21589 with a set of older, previously disclosed CVEs rolled into the same fixed releases (dependency updates). The new, Atlassian-assigned, high-severity item is CVE-2026-21589 — that is the one driving the urgency. Atlassian Data Center has a standing history of pre-auth vulnerabilities in internet-exposed instances, and the pattern holds: the exposure that matters is an on-prem Confluence or Jira reachable from the internet. If yours is, the patch window is measured in days, not weeks.