Vulnerability
Published 2026-10-05
Verified 2026-10-07

Atlassian CVE-2026-21589 (CVSS v4 9.3): unauthenticated file read in eight self-hosted Data Center products, including Jira, Confluence, Bitbucket and Crowd

Atlassian published a security advisory on 5 October 2026 for CVE-2026-21589, an arbitrary file access flaw (recorded as path traversal) in Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. An attacker with no login can read specific files inside the web application root directory, but must already know each file's exact name and path; the flaw does not let them list directory contents. Atlassian says some configurations hold sensitive files there, which raises the risk. Atlassian rates it Critical, 9.3 under CVSS v4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H), as its own internal assessment. All versions before the listed fixes are affected, which can include end-of-life versions. Affected Atlassian Cloud products are already patched and Atlassian says its investigation found no evidence of exploitation there; Bitbucket Cloud is not affected. For self-hosted instances Atlassian says it cannot confirm whether any have been hit, and tells customers to search access logs for requests where .. sits directly next to /, \ or :: (after URL-decoding up to twice). It offers three temporary blocking rules (a WAF or proxy regex, a Tomcat RewriteValve rule, and a file change; Crucible and Fisheye only get the first) and says they are not a replacement for patching. The Hacker News notes the CVE record lists different fixed versions from the advisory for Crowd and Bamboo, and also lists the older Server editions as affected with no fixed versions; go by the advisory and the product tickets. Primary: Atlassian security advisory. UPDATE (watchTowr Labs, 6 Oct 2026): watchTowr published a technical analysis, a Python proof of concept and a detection artefact generator. It traces the bug to the shared atlassian-plugins-webresource library, which turns :: back into / in web-resource download paths, so a request such as /download/resources/<plugin-key>/images/..::..::WEB-INF::web.xml walks out of a plugin's resource folder. watchTowr showed working routes on Jira, Confluence and Bitbucket. Reads stay inside the Tomcat web application, but that includes WEB-INF. On Jira set up to use Crowd as described in Atlassian's documentation, WEB-INF/classes/crowd.properties holds the Crowd application name and password; watchTowr used those to call the Crowd REST API, list users, create a new user and add it to jira-administrators. With public exploit code out, expect scanning and exploitation to follow quickly.

Product
Atlassian Data Center: Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd; plus Crucible and Fisheye (self-hosted)
Versions
All versions before the fixes. Fixed: Bitbucket DC 9.4.26, 10.2.8, 10.5.1; Confluence DC 9.2.26, 10.2.19; Jira Software DC 9.12.40, 10.3.26, 11.3.12; Jira Service Management DC 5.12.40, 10.3.26, 11.3.12; Bamboo DC 10.2.24, 12.1.12; Crowd DC 6.3.7, 7.0.3, 7.1.7, 7.2.4; Crucible and Fisheye 4.9.15. Cloud already patched.
CVSS
Critical (CVSS v4, Atlassian's own assessment)
Exploited in Australia?
unknown
Patch to
Upgrade every self-hosted Atlassian Data Center node to the fixed LTS version or later (list in Versions). Until then, take internet-facing instances off the public internet, including ones behind a login, or apply one of Atlassian's blocking rules at the WAF, proxy or Tomcat layer. Search access logs for .. next to /, \ or :: (URL-decode up to twice) and review what sits in the web application root. Plan off any remaining Server-edition installs, which the CVE record lists with no fix. Since public exploit code is out, treat this as urgent. If Jira or Confluence uses Crowd, rotate the Crowd application password held in WEB-INF/classes/crowd.properties after patching, check Crowd for users and group memberships you did not create (especially in jira-administrators), and search web logs for /download/resources/ requests containing ..:: sequences.

Primary: Atlassian — CVE-2026-21589 Arbitrary File Access Vulnerability impacts Multiple Products (advisory release 5 Oct 2026) · Vendor: Atlassian Jira ticket CONFSERVER-104488 (Confluence fix and mitigations; sibling tickets BSERV-20604, JRASERVER-79546, JSDSERVER-16809, BAM-26567, CWD-6610, CRUC-8741, FE-7583) · CVE: CVE-2026-21589 · watchTowr Labs — Atlassian Jira, Confluence (and more) pre-auth arbitrary file read CVE-2026-21589: analysis and PoC (6 Oct 2026)

vulnerabilities