Atlassian Data Center: critical flaw lets anyone read files on Jira, Confluence and Bitbucket servers

Atlassian disclosed on 5 October 2026 CVE-2026-21589 (CVSS 9.3), a path traversal flaw in eight self-hosted products, including Jira, Confluence and Bitbucket Data Center. No login is needed to read files from the application’s web root; Cloud is already patched, but on-premises instances must be updated now.

What happened

On 5 October 2026, Atlassian published an advisory for CVE-2026-21589, an arbitrary file access vulnerability rated 9.3 (critical) under CVSS 4.0. A remote attacker with no account can retrieve files located in the web application’s root directory. The attacker must already know the exact name and path of the file, as the flaw does not allow listing directories. CERT-FR relayed the fixes in advisory CERTFR-2026-AVI-1264 on 6 October.

Atlassian says its Cloud products have been patched and that its investigation found no evidence of exploitation; it also warns that it cannot tell whether a given self-hosted instance has been targeted.

Who is affected

All versions before the following fixed releases:

  • Jira Software Data Center: 9.12.40, 10.3.26, 11.3.12
  • Jira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12
  • Confluence Data Center: 9.2.26, 10.2.19
  • Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1
  • Bamboo Data Center: 10.2.24, 12.1.12
  • Crowd Data Center: 6.3.7, 7.0.3, 7.1.7, 7.2.4
  • Fisheye and Crucible: 4.9.15

What to do now

  1. Update each instance to the fixed release of its branch, or to the latest version.
  2. If you cannot update today, remove the instance from the internet (VPN or IP allow-list only), as Atlassian recommends.
  3. As a stopgap, block on your reverse proxy or WAF any request where .. sits right next to /, a backslash or ::, including URL-encoded and double-encoded forms; Atlassian’s advisory gives a ready-made regular expression.
  4. Search your access logs for such sequences, decoding URLs up to twice. A broad first pass: zgrep -icE '[.][.]|%(25)*2e' access.log*, then refine with Atlassian’s pattern.
  5. If you find hits, treat any secret stored in the web root as exposed and rotate it.

Our take

Jira, Confluence and Bitbucket hold a company’s tickets, documentation and source code, and they are frequently left open to the internet for convenience. A collaboration tool reachable without a VPN is a front door: patch quickly, and ask whether it really needs to be public at all.

Sources

How we choose, verify and write our analyses →

Is your own server exposed? Run a free check — public information only, no intrusion:

Check a server Check a website

Worried your servers are exposed? Our team audits, patches and monitors Linux and cloud infrastructure 24/7.

Talk to an expert Our managed server services →