Key points
- Atlassian has fixed CVE-2026-21589, a critical flaw rated 9.3 on the CVSS 4.0 scale that lets unauthenticated attackers read files from the web application root of eight self-hosted products, including Bitbucket, Confluence, Jira Software and Bamboo.
- Cloud customers need take no action, as Atlassian has patched affected Cloud products and found no evidence of exploitation there, while self-hosted users should upgrade to fixed releases such as Confluence 9.2.26 or 10.2.19 and Jira Software 9.12.40, 10.3.26 or 11.3.12.
- Where patching isn't immediately possible, Atlassian recommends taking internet-facing instances offline or applying a web application firewall rule, a Tomcat RewriteValve configuration, or a urlrewrite.xml rule for Bitbucket to block directory traversal attempts.
Collaboration vendor Atlassian has released fixes for a critical vulnerability that lets unauthenticated attackers read files from the web application root of eight of its self-hosted products.
The flaw is tracked as CVE-2026-21589 and affects Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd Data Center, along with the Crucible and Fisheye code review tools.
In its advisory Atlassian said every version prior to the fixed releases was vulnerable.
The company rated the bug 9.3 out of 10.0 on the CVSS 4.0 scale, while noting this was its own internal assessment and that customers should judge how it applied to their environments.
Attackers face one hurdle, as exploitation requires knowing the exact name and path of the target file, and the flaw cannot be used to list directory contents.
Nevertheless, Atlassian products install to well-documented default locations.
Atlassian itself warned that some configurations could leave sensitive files exposed, raising the risk.
No action is required by Cloud customers with Atlassian saying it had patched affected Cloud products and found no evidence of exploitation there.
Fixed releases include Confluence 9.2.26 and 10.2.19, Jira Software 9.12.40, 10.3.26 and 11.3.12, and Bitbucket 9.4.26, 10.2.8 and 10.5.1.
For those unable to patch immediately, Atlassian's first recommendation is to take internet-facing instances offline, including those protected by user authentication.
Failing that, it offered three stopgaps: a web application firewall rule, a Tomcat RewriteValve configuration, or for Bitbucket, a rule added to its urlrewrite.xml file.
All three block requests containing two dots next to a path separator, the signature of directory traversal, where an attacker uses "../" sequences to climb out of the folder a web server is meant to serve.
Security teams were also told to search access logs for the same pattern, decoding each request line up to twice beforehand, since attackers routinely double-encode characters to slip past filters.
The disclosure adds to a chequered record for Atlassian's self-hosted software, with Confluence flaws CVE-2022-26134 and CVE-2023-22515 both exploited in the wild soon after they surfaced.

HPE Networking Day Sydney
iTnews Resilience, Rewired Breakfast
RIMPA Live Convention 2026
What’s Next?
iTnews Benchmark Security Awards 2026



