Critical Atlassian Flaw Lets Attackers Read Your Files: Patch Data Center Now
Atlassian has released patches for a CVSS 9.3 vulnerability that lets unauthenticated attackers read specific files from eight of its most widely used self-hosted products. No login required. If you're running Confluence, Jira, or Bitbucket on your own servers, this needs your attention today.
What Happened
Atlassian disclosed CVE-2026-21589 on 5 October 2026. It is a critical arbitrary file access flaw in the Data Center editions of Confluence, Jira Software, Jira Service Management, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye. An unauthenticated attacker who knows a file's exact name and path can read it directly from the web application root. No credential, no session, no prior access needed.
Atlassian has already patched its Cloud products, so there is nothing to do there. Self-hosted installations have not been patched for you. Those are on you.
Who's Affected
Any business running a self-hosted Atlassian Data Center product is exposed, including instances running inside a private network. On-premises deployments are common in professional services firms, financial advisory practices, engineering businesses, and healthcare organisations where data residency or compliance requirements prevent a move to cloud. All versions of the eight affected products are vulnerable until patched, and fixed versions are available for each.
| Product | Fixed Versions | Status |
|---|---|---|
| Confluence Data Center | 9.2.26 or 10.2.19 | Patch available |
| Jira Software Data Center | 9.12.40, 10.3.26 or 11.3.12 | Patch available |
| Jira Service Management Data Center | 5.12.40, 10.3.26 or 11.3.12 | Patch available |
| Bitbucket Data Center | 9.4.26, 10.2.8 or 10.5.1 | Patch available |
| Bamboo, Crowd, Crucible, Fisheye | See Atlassian advisory | Patch available |
| Atlassian Cloud (all products) | Patched by Atlassian | Already patched |
What to Do Right Now
With OAIC enforcement getting more active around demonstrable security controls, leaving a CVSS 9.3 vulnerability sitting on a server isn't just a technical oversight. It's a compliance exposure. Here's what to do:
- Identify your installations. Check whether any Atlassian tools in your environment are self-hosted or cloud. If you're not sure, your IT team or managed service provider can tell you in minutes.
- Apply the patches immediately. Upgrade to the fixed version for your release line, such as Confluence 9.2.26, Jira 10.3.26, or Bitbucket 9.4.26. Consult the Atlassian advisory for the patched versions of Bamboo, Crowd, Crucible, and Fisheye.
- Can't patch right now? Apply one of Atlassian's temporary mitigations (a WAF rule, a Tomcat RewriteValve configuration, or the Bitbucket urlrewrite.xml change) and, where possible, take the instance off the internet until you can upgrade.
- Review your logs. Check web server access logs for unauthenticated requests containing path traversal patterns, or requests for unexpected file paths that returned 200 OK responses.
Frequently Asked Questions
Which Atlassian products are affected by CVE-2026-21589?
Eight self-hosted Atlassian products are affected: Confluence, Jira Software, Jira Service Management, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye. All versions before the fixed releases listed in Atlassian's advisory are vulnerable.
Am I affected if I use Atlassian Cloud (Jira Cloud, Confluence Cloud)?
No. Atlassian has already patched its affected Cloud products and no customer action is required. CVE-2026-21589 only affects self-hosted installations running on your own servers or infrastructure.
Is there a workaround if I can't patch immediately?
Temporary mitigations exist, but they are not a substitute for patching. Atlassian has published three options: a web application firewall rule that blocks path traversal patterns, a Tomcat RewriteValve configuration for Confluence, Jira, Bamboo and Crowd, and a urlrewrite.xml change for Bitbucket. Atlassian also recommends removing the instance from the internet until you can patch or mitigate.
How do I know if my Atlassian Data Center instance has been compromised?
Review your web server access logs for unauthenticated requests containing path traversal patterns (such as ../) or requests for unexpected file paths in the web application root that returned 200 OK. If you're unsure what to look for, contact your managed IT provider. A log review is a quick task for someone who knows what they're doing.
Not sure if your Atlassian tools are patched?
We can check your patch status, review your logs, and handle the upgrade for you, so you're not left guessing. Talk to the All IT team today.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
