Tech News

Critical Atlassian Flaw Lets Attackers Read Files in Jira, Confluence, and Bitbucket

Do you manage a Jira, Confluence, or Bitbucket instance hosted on your own servers? Atlassian has issued an alert about a critical security flaw rated 9.3 out of 10 that allows remote file reads without authentication. Here’s what you need to know about this vulnerability and how to protect yourself.

On October 5, 2026, Atlassian published a security bulletin dedicated to vulnerability CVE-2026-21589. This flaw affects eight self-hosted products from Atlassian: Jira Software Data Center, Jira Service Management Data Center, Confluence Data Center, Bitbucket Data Center, Bamboo Data Center, Crowd Data Center, as well as Crucible and Fisheye. This is therefore a cross-cutting flaw across the vendor’s product portfolio, with a CVSS v4.0 score of 9.3 out of 10.

By exploiting this vulnerability, an unauthenticated attacker can access certain files located in the web application's root directory. However, there is one condition, as stated in the security bulletin. "Exploitation requires prior knowledge of the exact name and path of the target file. This vulnerability does not allow attackers to enumerate or list directory contents.", Atlassian explains. The vendor acknowledges that, depending on the configuration, sensitive files may be present in this directory.

Versions That Fix CVE-2026-21589

For Cloud customers, there is nothing to do: Atlassian has already patched its services and says it found no evidence of exploitation. For everything hosted on your own infrastructure, however, it’s up to you to take action.

Atlassian recommends upgrading to one of the following patched versions, or to a later release:

  • Bitbucket Data Center : 9.4.26, 10.2.8 et 10.5.1
  • Confluence Data Center : 9.2.26 et 10.2.19
  • Jira Software Data Center : 9.12.40, 10.3.26 et 11.3.12
  • Jira Service Management Data Center : 5.12.40, 10.3.26 et 11.3.12
  • Bamboo Data Center : 10.2.24 et 12.1.12
  • Crowd Data Center : 6.3.7, 7.0.3, 7.1.7 et 7.2.4
  • Crucible et Fisheye : 4.9.15

It is important to patch because Atlassian products exposed to the Internet are a recurring target, including by ransomware groups.

Can’t Patch Right Away?

If you are unable to patch right now, Atlassian recommends taking the instance offline from the Internet until the fix is applied. But what’s interesting is that the vendor also provides mitigation measures based on rules designed to block certain sequences in the URL.

  • WAF or proxy rule : valid for all products, based on a regular expression provided in the bulletin.
  • Tomcat RewriteValve : for Confluence, Jira, Jira Service Management, Bamboo and Crowd. You need to place the rule in the server.xml file, then create or complete the rewrite.config file in the application’s WEB-INF directory. Node by node, with a restart.
  • Rule in urlrewrite.xml : reserved for Bitbucket, by adding a rule at the top of the file. It must be deployed on all nodes in the cluster, as well as on Bitbucket mirrors and mirror farm nodes.

The regex for the WAF and the rewrite rules are detailed in Atlassian’s security bulletin. It’s up to you now!

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.