Critical Atlassian Flaw Lets Attackers Read Files in Jira, Confluence, and Bitbucket
Do you manage a Jira, Confluence, or Bitbucket instance hosted on your own servers? Atlassian has issued an alert about a critical security flaw rated 9.3 out of 10 that allows remote file reads without authentication. Here’s what you need to know about this vulnerability and how to protect yourself.
On October 5, 2026, Atlassian published a security bulletin dedicated to vulnerability CVE-2026-21589. This flaw affects eight self-hosted products from Atlassian: Jira Software Data Center, Jira Service Management Data Center, Confluence Data Center, Bitbucket Data Center, Bamboo Data Center, Crowd Data Center, as well as Crucible and Fisheye. This is therefore a cross-cutting flaw across the vendor’s product portfolio, with a CVSS v4.0 score of 9.3 out of 10.
By exploiting this vulnerability, an unauthenticated attacker can access certain files located in the web application's root directory. However, there is one condition, as stated in the security bulletin. "Exploitation requires prior knowledge of the exact name and path of the target file. This vulnerability does not allow attackers to enumerate or list directory contents.", Atlassian explains. The vendor acknowledges that, depending on the configuration, sensitive files may be present in this directory.
Versions That Fix CVE-2026-21589
For Cloud customers, there is nothing to do: Atlassian has already patched its services and says it found no evidence of exploitation. For everything hosted on your own infrastructure, however, it’s up to you to take action.
Atlassian recommends upgrading to one of the following patched versions, or to a later release:
- Bitbucket Data Center : 9.4.26, 10.2.8 et 10.5.1
- Confluence Data Center : 9.2.26 et 10.2.19
- Jira Software Data Center : 9.12.40, 10.3.26 et 11.3.12
- Jira Service Management Data Center : 5.12.40, 10.3.26 et 11.3.12
- Bamboo Data Center : 10.2.24 et 12.1.12
- Crowd Data Center : 6.3.7, 7.0.3, 7.1.7 et 7.2.4
- Crucible et Fisheye : 4.9.15
It is important to patch because Atlassian products exposed to the Internet are a recurring target, including by ransomware groups.
Can’t Patch Right Away?
If you are unable to patch right now, Atlassian recommends taking the instance offline from the Internet until the fix is applied. But what’s interesting is that the vendor also provides mitigation measures based on rules designed to block certain sequences in the URL.
- WAF or proxy rule : valid for all products, based on a regular expression provided in the bulletin.
- Tomcat RewriteValve : for Confluence, Jira, Jira Service Management, Bamboo and Crowd. You need to place the rule in the
server.xmlfile, then create or complete therewrite.configfile in the application’sWEB-INFdirectory. Node by node, with a restart. - Rule in urlrewrite.xml : reserved for Bitbucket, by adding a rule at the top of the file. It must be deployed on all nodes in the cluster, as well as on Bitbucket mirrors and mirror farm nodes.
The regex for the WAF and the rewrite rules are detailed in Atlassian’s security bulletin. It’s up to you now!


