Atlassian File Access Vulnerability in Data Center

Atlassian Data Center file access vulnerability CVE-2026-21589 (CVSS 9.3) hits eight products with no login. No exploitation reported yet. Patch now.

The Atlassian file access vulnerability CVE-2026-21589 (CVSS 9.3) lets an unauthenticated attacker read files from the web root of eight self-hosted products: Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible and Fisheye. Every version is affected until it is upgraded. No exploitation has been reported so far, and the patched releases are out. What decides the damage is what happens to be sitting in the web root.

What Happened

Atlassian published its advisory on October 5, 2026, after a mitigation file reportedly appeared on the public Jira ticket on October 2 (per watchTowr, not independently confirmed). The Atlassian file access vulnerability is a path traversal: an attacker without any account can request specific files in the web application root directory that should be out of reach. The attacker has to know the exact file name and path, and cannot list a directory. The 9.3 is a CVSS v4.0 score.

All versions of Bitbucket, Bamboo, Crowd, Confluence, Jira Software and Jira Service Management Data Center are affected, as are Crucible and Fisheye. Fixed releases: Bitbucket 9.4.26, 10.2.8 and 10.5.1; Bamboo 10.2.24 and 12.1.12; Confluence 9.2.26 and 10.2.19; Crowd 6.3.7, 7.0.3, 7.1.7 and 7.2.4; Crucible and Fisheye 4.9.15; Jira Service Management 5.12.40, 10.3.26 and 11.3.12; Jira Software 9.12.40, 10.3.26 and 11.3.12. Atlassian’s cloud services are already patched. Both Atlassian and watchTowr state that exploitation in the wild has not been seen, and as of October 6 the CVE was not in CISA’s Known Exploited Vulnerabilities catalog.

Why It Matters

A file-read flaw sounds minor until you look at the products. Bitbucket holds source code, Bamboo builds and ships it, Crowd handles identity and single sign-on, and Jira and Confluence hold plans, tickets and documentation. CSO Online points out that the CVSS vector assigns no integrity or availability impact to the vulnerable server itself but a high impact on systems downstream: the server is untouched, the keys it guards are not. watchTowr warns that with SSO through Crowd, authentication details sit in plaintext at a predictable path, so a reachable Crowd could let an attacker create their own admin users.

Knowing the exact file path is a lower bar than it looks: the products are downloadable, so anyone can learn where files live, and web roots on old servers collect configuration copies and backups nobody remembers. We saw the same shape in our GitLab path traversal post and the earlier GitLab Oj Spill case: unauthenticated flaws in self-hosted developer infrastructure. watchTowr notes that ransomware groups and APTs have exploited this type of flaw before. CSO Online adds that Atlassian no longer ships binary patches, so the fix is a move to a new maintenance release. That makes it an upgrade project, not a quick fix.

What You Should Do Now

  1. Inventory every Data Center instance of the eight products, internet-facing ones first, and upgrade each to a fixed release from the list above.
  2. If an instance cannot be upgraded today, take it off the internet or restrict external access, including instances that require login: a login page does nothing against an unauthenticated flaw. Atlassian also describes a WAF or proxy rule, a Tomcat RewriteValve rule (Bamboo, Confluence, Crowd, Jira) and a urlrewrite.xml rule (Bitbucket), applied on every node with a restart. Atlassian calls these limited and no replacement for patching.
  3. Search your access logs. A practical check is to decode each request line up to twice and look for two dots directly next to a slash, backslash or double colon. If you find a hit, assume the file was read.
  4. Rotate every credential, token and key that could have lived in a web root or application directory, and treat Crowd SSO secrets as exposed if Crowd was reachable. Then move secrets out of web roots for good.
  5. Watch the CISA KEV catalog for CVE-2026-21589. The current status is “no exploitation reported”, and that can change.

DIESEC Perspective

Assessment: long-running collaboration servers tend to accumulate files in their application directories that nobody inventoried, such as a configuration copy, an old backup or a credentials file from a migration. A flaw like this turns that housekeeping debt into an external exposure. Instances that were patched on schedule can still carry the leftovers.

Not sure which of your Atlassian instances are reachable from the internet, or what sits in their web roots? Contact DIESEC for a rapid exposure review and secrets check.

Sources: Atlassian advisory | watchTowr | CSO Online | SecurityWeek
Published: 2026-10-08 | Category: Vulnerabilities & Patches | ~5 min read