VMTech
Discuss a project →

Atlassian patches critical file-read flaw in eight Data Center products

Atlassian patches critical file-read flaw in eight Data Center products

Atlassian has disclosed and patched CVE-2026-21589, a critical path traversal vulnerability rated 9.3 out of 10 under CVSS v4.0. The issue affects eight self-hosted Data Center products and can allow an unauthenticated attacker to read specific known files from a product’s web application root directory.

The affected products are Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. An attacker must know the exact name and path of a target file; the flaw does not permit directory listing.

Fixed versions and exposure

Atlassian said all affected cloud products have already been patched, and cloud customers need take no action. Bitbucket Cloud is not affected. The company advises Data Center customers to move to a listed fixed release, preferably a supported long-term support release or later where appropriate.

Fixed versions include Bitbucket Data Center 9.4.26, 10.2.8 and 10.5.1; Confluence Data Center 9.2.26 and 10.2.19; and Jira Software Data Center 9.12.40, 10.3.26 and 11.3.12. Jira Service Management Data Center is fixed in 5.12.40, 10.3.26 and 11.3.12, while Bamboo Data Center is fixed in 10.2.24 and 12.1.12.

Crowd Data Center fixes are listed as 6.3.7, 7.0.3, 7.1.7 and 7.2.4. Crucible and Fisheye are fixed in version 4.9.15. Atlassian noted an inconsistency in its Crowd 7.1 documentation: a ticket’s fix-version field named 7.1.7, while a table in that ticket showed 7.1.6 and also listed it as affected.

Why the vulnerability requires prompt action

A path traversal request uses a constructed file path to reach files that should not be accessible. Atlassian said the web application root can contain sensitive files in some configurations, increasing the risk even though an attacker cannot browse the directory to discover filenames.

The CVSS assessment describes the vulnerability as network-reachable, requiring neither privileges nor user interaction. It assigns high confidentiality impact to the vulnerable system, no integrity or availability impact, and high impact on other systems. Atlassian did not identify which files may be sensitive or which configurations create that exposure.

Atlassian recommends taking an instance offline where an immediate upgrade is not possible. Any publicly reachable instance, including one that presents a login screen, should be restricted from external network access until it is upgraded or a temporary blocking control has been applied.

Temporary controls and log review

The vendor describes three limited mitigations. All block URLs containing .. directly next to /, \ or ::, including URL-encoded variants. A web application firewall or reverse proxy rule can protect all eight products.

Confluence, Jira Software, Jira Service Management, Bamboo and Crowd can also use a Tomcat RewriteValve rule on every node, followed by a shutdown and restart. Bitbucket can use a rule in urlrewrite.xml on each node, mirror and mirror-farm node, then restart. Crucible and Fisheye have only the WAF or reverse-proxy option. Atlassian stresses that these controls do not replace patching.

For retrospective checks, Atlassian tells security teams to inspect access logs by URL-decoding each request line up to twice and searching for the relevant traversal patterns, or by applying the blocking pattern to raw log lines. Its investigation found no evidence of exploitation in affected cloud products, but the company cannot confirm whether individual self-hosted instances were affected. Businesses should identify internet-exposed Data Center deployments, deploy the applicable fixed version, retain temporary blocking controls during the change window, and review logs for traversal attempts as part of their incident assessment.

#atlassian#cybersecurity#vulnerability#datacenter
Open analytics
On the site 0 views
min read 4 06.10.2026
Instagram

Atlassian patches critical file-read flaw in eight Data Center products

Open the post on Instagram ↗