Atlassian warns of critical file-access flaw in Jira, Confluence

Critical File-Access Flaw Hits Atlassian Products, Urgent Patching Advised

Atlassian has issued a critical security warning for its self-hosted Data Center products, including Confluence, Jira, and Bitbucket. A vulnerability tracked as CVE-2026-21589 allows an unauthenticated attacker to access specific files within the affected application’s web root directory, posing a significant threat to users with self-hosted instances.

The issue is particularly concerning because it can be exploited without requiring knowledge of the target file or path. However, exploitation does require knowing the exact name and location of the desired file. This means that attackers may need some prior reconnaissance or inside information to carry out an attack.

The vulnerability affects all product versions released before specific patch releases for each affected application. Atlassian has provided a detailed list of impacted products and their corresponding patched versions: Bitbucket Data Center (9.4.26, 10.2.8, 10.5.1), Confluence Data Center (9.2.26, 10.2.19), Jira Service Management Data Center (5.12.40, 10.3.26, 11.3.12), and others.

Atlassian has emphasized the importance of urgent patching for self-hosted instances. The company advises system administrators to apply security updates as soon as possible to prevent potential attacks. For customers who cannot immediately patch their systems, Atlassian recommends restricting external network access, including for internet-facing instances that require user authentication.

In addition to these temporary mitigations, the company suggests implementing web application firewalls (WAF) or proxy rules blocking specified traversal patterns across all affected products. Atlassian has provided step-by-step instructions and configuration details to help administrators implement these measures.

The changes must be applied to every cluster node, including Bitbucket mirrors and mirror farm nodes. It’s essential for administrators to review access logs for the traversal patterns described in the bulletin to identify potential attacks.

Although Atlassian currently has no evidence that CVE-2026-21589 is being exploited in attacks, the company urges administrators to take immediate action to prevent potential breaches. Self-hosted instance customers are advised to engage with their local security team to review and implement these measures as soon as possible.

To protect your self-hosted instances from this critical vulnerability, it’s essential to apply the recommended patches or temporary mitigations immediately. If you’re unsure about how to proceed, consult Atlassian’s advisory for detailed instructions and configuration details. Remember that prompt action is crucial in preventing potential attacks and safeguarding your data.


Source: Bleeping Computer — 2026-10-06