Back to Newsroom
Threat Intel

Atlassian Patches Critical Unauthenticated File-Read Flaw Across 8 Products

A maximum-severity path traversal bug lets unauthenticated attackers read sensitive files from eight self-hosted Atlassian products. Patches are out now — unpatched instances need an immediate mitigation.

Atlassian Patches Critical Unauthenticated File-Read Flaw Across 8 Products

Atlassian has shipped fixes for a maximum-impact path traversal vulnerability that lets an attacker with no login at all read arbitrary files from the web application root of eight self-hosted Data Center products — no credentials, no user interaction, nothing but network access required.

What happened

Tracked as CVE-2026-21589 and rated 9.3 out of 10 on CVSS, the flaw lives in how affected products resolve file paths inside their web application root directory. An attacker who knows (or guesses) a file's exact name and path can retrieve it directly, and in some configurations can also enumerate what else lives in that directory — a problem Atlassian flags as potentially exposing sensitive data depending on deployment.

The bug touches Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye Data Center — effectively Atlassian's entire self-hosted product line. Cloud instances have already been patched by Atlassian directly, and cloud customers don't need to do anything. Bitbucket Cloud was never affected.

Fixed versions are available now for every product. Atlassian recommends upgrading to a fixed long-term support release or later; versions that have already reached end-of-life may still carry the flaw and won't receive a patch.

Why it matters

A 9.3 CVSS score reflects a vulnerability that's remotely reachable, needs no privileges and no user interaction, and carries a high confidentiality impact — both on the vulnerable instance and on connected systems. Atlassian hasn't specified which sensitive files or configuration data are most at risk, which means every self-hosted deployment should be treated as potentially exposed until patched.

This isn't the first time a flaw like this has hit Atlassian's self-hosted line: CVE-2021-26086, a comparable path traversal in Jira Server and Data Center, was added to CISA's Known Exploited Vulnerabilities catalog in 2021 after real-world abuse. Atlassian says it hasn't found evidence of exploitation for this new flaw so far, but — by its own admission — it also can't confirm whether any given self-hosted instance has been hit.

What to do

  • Patch first. Upgrade affected products to the fixed versions Atlassian has published, prioritizing any instance reachable from the public internet, especially ones that don't require authentication.
  • If you can't patch immediately, apply Atlassian's interim mitigation: a web application firewall or reverse-proxy rule blocking requests containing traversal sequences (../, ..\, or ::, including URL-encoded forms) works across all eight products. Confluence, Jira Software, Jira Service Management, Bamboo and Crowd also support a Tomcat-level rewrite rule; Bitbucket has an equivalent urlrewrite.xml change. Atlassian is explicit that these mitigations are a stopgap, not a substitute for patching.
  • Check your logs. Search access logs for traversal patterns, URL-decoding each request line up to twice before matching — a single decode pass can miss double-encoded payloads.
  • Restrict exposure for any instance you can't patch or take offline: limit it to trusted networks until the fix is applied.

Given the active-exploitation history of similar Atlassian flaws, treat this as urgent patching, not routine maintenance.

SHARE