On October 5, Atlassian published an emergency advisory for CVE-2026-21589, a critical (CVSS 9.3) arbitrary file access flaw affecting eight self-hosted products. An unauthenticated remote attacker can retrieve specific files from the application’s web root. Atlassian urges customers to patch immediately or pull instances off the public internet. As of October 6, no in-the-wild exploitation has been reported, and Atlassian Cloud has already been patched.

What happened

The bug sits in the web application’s request handling layer, shared across the Data Center and Server product line. A crafted request lets a client read files inside the deployed web application root without logging in. Atlassian rates it CVSS 9.3 with no privileges or user interaction required.

watchTowr published analysis the same week and confirms the issue is pre-authentication across Jira and Confluence. The primary mitigating factor is that the attacker must already know the exact filename and path. The flaw does not allow directory listing or browsing, so exploitation depends on predictable file locations.

Affected products and fixed versions

Every currently supported Data Center release of the following is affected prior to the fixed builds:

ProductFixed versions
Bitbucket Data Center9.4.26, 10.2.8, 10.5.1
Confluence Data Center9.2.26, 10.2.19
Jira Software Data Center9.12.40, 10.3.26, 11.3.12
Jira Service Management Data Center5.12.40, 10.3.26, 11.3.12
Bamboo Data Center10.2.24, 12.1.12
Crowd Data Center6.3.7, 7.0.3, 7.1.7, 7.2.4
Crucible4.9.15
Fisheye4.9.15

Verify exact build numbers against Atlassian’s advisory before upgrading, as the list above reflects reporting at the time of writing.

Why it matters

Individually, a known-path file read is limited. In the context of a dev-infrastructure stack it is not. Atlassian’s products typically sit at the center of source control (Bitbucket), CI/CD (Bamboo) and identity (Crowd), and web roots in these deployments can hold static assets, configuration fragments, and bundled resources whose paths are identical across every installation because they ship with the product. Attackers do not need to guess when the layout is public. Pre-auth file reads in this product family have historically been chained with leaked configuration or tokens into full compromise, and the stakes are higher in an environment where pipelines hold deployment credentials.

Treat internet-exposed Jira and Confluence instances as the highest priority: they are the most commonly published, and bug-class details are already public through the watchTowr write-up, which shortens the window before exploitation tooling appears.

Mitigation

  1. Patch. Upgrade each affected product to its fixed version in the table above. Atlassian says Cloud customers need take no action.
  2. If you cannot patch immediately, remove the instance from the public internet (VPN or IP allowlist) and apply the WAF rule or server-level configuration change described in Atlassian’s advisory. Atlassian stresses this does not replace patching.
  3. Hunt. Review reverse proxy and application access logs back to at least October 1 for unauthenticated requests with path traversal sequences (.., encoded %2e%2e, double-encoding) or unusual requests to static/web-root paths from external IPs.
  4. Assume exposure of secrets in any file under the web root of an instance you suspect was probed. Rotate credentials stored there, along with any tokens that Bamboo, Bitbucket or Crowd use to integrate with downstream systems.
  5. Inventory. Fisheye and Crucible are easy to forget; confirm they are not running unpatched on forgotten hosts.

Sources