Skip to content
Security & Trust

Atlassian flaw lets outsiders read known files without a login

CVE-2026-21589 affects eight Atlassian products. Atlassian says no credentials are needed to exploit it.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Atlassian flaw lets outsiders read known files without a login
In brief
  • Atlassian says CVE-2026-21589 lets an unauthenticated attacker read specific files in the web root of eight Atlassian products, if the attacker knows the exact path.
  • Because no credentials are needed, a login page gives no protection here. Exposure depends on what files sit in the web root.
  • Teams should list affected products, restrict internet access, patch or mitigate, and search access logs using Atlassian's guidance.

A login page feels like a wall. This week's Atlassian advisory shows how that comfort can mislead. Atlassian says this flaw needs no credentials, so here the login offers no protection.

What Atlassian disclosed

Atlassian published an advisory on October 5, 2026 for CVE-2026-21589. It says an unauthenticated attacker can reach specific files inside a product's web application root directory. That is the folder holding the application's own files.

The advisory names eight products. Six are Data Center editions: Bitbucket, Confluence, Bamboo, Crowd, and the two Jira products, Jira Service Management and Jira Software. The other two are Crucible and Fisheye. Atlassian says every version before the listed fixed releases is affected.

9.3 (Critical)
Atlassian severity rating (CVSS 4.0)
Source: Atlassian security advisory, CVE-2026-21589 (October 5, 2026)
8
Atlassian products listed as affected
Source: Atlassian security advisory, CVE-2026-21589 (October 5, 2026)

Atlassian calls the 9.3 score its own assessment. It tells customers to judge how it applies to their environment.

How the flaw works

Atlassian's temporary fix is a filter. It blocks web addresses that put two dots next to a slash, a backslash or a double colon, including encoded forms of those characters.

Two dots in a path are the standard way to step up one folder. The mitigation therefore suggests a path-handling weakness. A crafted address could climb out of the folder the application meant to serve and reach files beside it. Both points are our inference. Atlassian does not name the root cause.

Atlassian says the files are within the web application root directory. This suggests the exposure is bounded by that folder, not the whole server. That reading is ours, not Atlassian's wording. The limits are real. The attacker must know the exact file name and path. The flaw cannot list a directory's contents. Atlassian says some configurations hold sensitive files, which raises the risk.

Why a login is not a shield

The lesson here is that exposure should not be ranked by whether a system asks for a password. Atlassian says no credentials are needed for this flaw, so the sign-in screen does not help. The better question is what a stranger can fetch.

Atlassian advises restricting outside access to internet-facing instances until they are patched or mitigated. It says this applies even where users must sign in. Horizon3 published its own analysis on October 6 and reaches the same conclusion. In its words, an internet-facing server stays exposed even when it asks users to sign in.

The people carrying the risk are the administrators of self-managed servers. Atlassian reports that its Cloud products are already patched. It found no evidence of exploitation there. Cloud customers need take no action. Data Center customers must do the work themselves.

What the sources do not say

Neither source says whether the flaw is being exploited against Data Center installations. Atlassian says it cannot confirm whether any customer instance has been affected. It asks customers to have their security teams check access logs.

Atlassian's log guidance offers two routes. One is to decode each request line, up to two times, and look for two dots next to a slash, backslash or double colon. The other is to search the raw log lines with the vendor's pattern.

Up to 2
URL-decoding passes Atlassian says to apply before searching logs
Source: Atlassian security advisory, CVE-2026-21589 (October 5, 2026)

Questions to put to your team

Ask which of the eight products you run, and in which versions. Ask whether any are reachable from the internet, and whether that access is still needed. Horizon3 adds that older installations outside vendor support may be affected too. It says they should move to a supported release that contains the fix.

Ask who owns the fix. Atlassian recommends upgrading to a fixed release. Where that cannot happen yet, it offers two interim paths. One is a filtering rule at the firewall or proxy. The other is a rewrite rule in Tomcat, the web server component inside these products, or a vendor rule for Bitbucket. Atlassian says to back up first and to apply the change on every node in a cluster.

Ask what sits in the web root. Atlassian ties the risk to the files present, so a team that knows what is there can size the exposure. Ask for the log search results too, in writing.

Horizon3 also sells a test for this flaw in its NodeZero platform. It is a vendor product and optional. The vendor advisory and a log review are the core steps.

A password guards what sits behind it. This flaw, Atlassian says, needs no password, so the question that matters is what a stranger could read.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Horizon3.ai.

Share this insight