Atlassian Data Centre products hit by unauthenticated file access vulnerability

By
Follow google news

Take internet-facing instances offline if they can't be patched immediately.

Key points

  • Atlassian has fixed CVE-2026-21589, a critical flaw rated 9.3 on the CVSS 4.0 scale that lets unauthenticated attackers read files from the web application root of eight self-hosted products, including Bitbucket, Confluence, Jira Software and Bamboo.
  • Cloud customers need take no action, as Atlassian has patched affected Cloud products and found no evidence of exploitation there, while self-hosted users should upgrade to fixed releases such as Confluence 9.2.26 or 10.2.19 and Jira Software 9.12.40, 10.3.26 or 11.3.12.
  • Where patching isn't immediately possible, Atlassian recommends taking internet-facing instances offline or applying a web application firewall rule, a Tomcat RewriteValve configuration, or a urlrewrite.xml rule for Bitbucket to block directory traversal attempts.
Atlassian Data Centre products hit by unauthenticated file access vulnerability

Collaboration vendor Atlassian has released fixes for a critical vulnerability that lets unauthenticated attackers read files from the web application root of eight of its self-hosted products.

The flaw is tracked as CVE-2026-21589 and affects Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd Data Center, along with the Crucible and Fisheye code review tools.

In its advisory Atlassian said every version prior to the fixed releases was vulnerable.

The company rated the bug 9.3 out of 10.0 on the CVSS 4.0 scale, while noting this was its own internal assessment and that customers should judge how it applied to their environments.

Attackers face one hurdle, as exploitation requires knowing the exact name and path of the target file, and the flaw cannot be used to list directory contents.

Nevertheless, Atlassian products install to well-documented default locations.

Atlassian itself warned that some configurations could leave sensitive files exposed, raising the risk.

No action is required by Cloud customers with Atlassian saying it had patched affected Cloud products and found no evidence of exploitation there.

Fixed releases include Confluence 9.2.26 and 10.2.19, Jira Software 9.12.40, 10.3.26 and 11.3.12, and Bitbucket 9.4.26, 10.2.8 and 10.5.1.

For those unable to patch immediately, Atlassian's first recommendation is to take internet-facing instances offline, including those protected by user authentication.

Failing that, it offered three stopgaps: a web application firewall rule, a Tomcat RewriteValve configuration, or for Bitbucket, a rule added to its urlrewrite.xml file.

All three block requests containing two dots next to a path separator, the signature of directory traversal, where an attacker uses "../" sequences to climb out of the folder a web server is meant to serve.

Security teams were also told to search access logs for the same pattern, decoding each request line up to twice beforehand, since attackers routinely double-encode characters to slip past filters.

The disclosure adds to a chequered record for Atlassian's self-hosted software, with Confluence flaws CVE-2022-26134 and CVE-2023-22515 both exploited in the wild soon after they surfaced.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Home Affairs orders gov-wide 'legacy' system stocktake within six months

Home Affairs orders gov-wide 'legacy' system stocktake within six months

OpenAI agent accessed "credentials" via Medicare data portal

OpenAI agent accessed "credentials" via Medicare data portal

Cisco says no workaround for exploited SD-WAN Manager flaw

Cisco says no workaround for exploited SD-WAN Manager flaw

NSW National Parks web app accessed by OpenAI agent

NSW National Parks web app accessed by OpenAI agent

Log In

  |  Forgot your password?