Skip to content
Brief Security & Trust ·

Atlassian warns of critical file-access flaw in Data Center products

The bug lets anyone on the network read certain files without logging in.

In brief
  • Atlassian said CVE-2026-21589 affects eight products in every version before the fixed releases, and rated it critical at 9.3.
  • No Cloud action is needed. For Data Center, Atlassian cannot confirm whether instances were affected and urges log checks.

Atlassian published an advisory on October 5, 2026 about CVE-2026-21589. It covers eight products: Data Center editions of Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd, plus Crucible and Fisheye. Every version before the fixed releases is affected. Atlassian said someone with no account can read chosen files in an app's web root folder. It rated the flaw critical, 9.3 out of 10. Horizon3.ai released a test on October 6.

The attacker must know a file's exact name and path, and cannot list folder contents, Atlassian said. It did not describe the method, but its stopgap rules block '..' beside slashes. That suggests requests that climb out of the intended folder; this is an inference from those rules. Atlassian said its Cloud products are patched and its investigation found no evidence of exploitation there. For Data Center, it said it cannot confirm whether instances were affected and urged log checks. The sources give no fixed version numbers.

Atlassian said a login alone does not protect an exposed system, so risk depends on which files sit within reach. This week, executives can ask: Which instances face the internet? Who owns them? What sits in their web roots? How fast can we patch? Until then, Atlassian advises cutting public access, or applying a firewall rule or Tomcat rewrite rules.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: Horizon3.ai, iTnews.