Eight self-hosted Atlassian Data Center products are affected by the same vulnerability. CVE-2026-21589 allows attackers to read files without logging in themselves. Patches are available. Users of Atlassian as a cloud service do not need to take any action.
Atlassian disclosed the vulnerability earlier this week and assigned it a CVSS 4.0 score of 9.3. It is a path traversal vulnerability in which an attacker can retrieve files from the web application’s root directory using a specially crafted file path. This is possible without login credentials. However, the attacker must know the exact name and location of a file. Without additional leaked information, exploiting the vulnerability therefore comes down to making a well-informed guess.
In some configurations, sensitive files are located in the affected directory, according to Atlassian. The advisory does not specify which files or configurations are affected.
The affected applications are Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye. All versions prior to the patched releases are vulnerable, including those that are end-of-life. Atlassian recommends upgrading to a patched LTS version.
Uncertainty regarding server editions
Interestingly, the CVE record differs from the advisory in some respects, as Hacker News notes. It also includes the Server editions, the older self-hosted product line that Atlassian began phasing out years ago in favor of the cloud. All versions of Bamboo, Bitbucket, Confluence, and Crowd Server are marked as vulnerable, with no fix available. The version numbers for Crowd and Bamboo also differ between the two documents.
Mitigations and log monitoring
According to Atlassian, anyone who cannot patch immediately should take the instance offline or isolate it from the internet. In addition, the company describes temporary blocking rules via a WAF, reverse proxy, Tomcat RewriteValve, or urlrewrite.xml. These block URLs in which ‘..’ appears immediately next to /, , or ::. The measures “are limited and are not a substitute for patching your instance,” Atlassian warns.
In the cloud, Atlassian found no evidence of exploitation. For self-hosted environments, “Atlassian cannot confirm whether your instances have been affected.” Security teams should therefore review their access logs.
Previous Atlassian vulnerabilities were indeed exploited. In November 2024, CISA added the similar Jira path traversal vulnerability CVE-2021-26086 to its list of actively exploited vulnerabilities. In 2022, Atlassian even urged customers to disable Confluence due to an RCE vulnerability. And with the Confluence vulnerability CVE-2023-22515, many users remained unpatched for a long time.