Atlassian patches critical arbitrary file-access bug across Jira, Confluence, Bitbucket
Atlassian disclosed CVE-2026-21589, a critical vulnerability letting unauthenticated attackers read specific files inside the web root of several self-hosted Data Center products, including Confluence, Jira, Bitbucket, Bamboo, Crowd, Crucible and Fisheye. Exploitation requires knowing the exact file name and path, and the flaw does not allow directory listing. Atlassian has released patched versions for each affected product and says Cloud customers are already protected.
GoKawiil's interpretation of the reporting above, not reported fact.
Because exploitation needs precise file-path knowledge rather than broad scanning, the risk may be most acute for attackers who already have some insight into a target's configuration, such as through leaked documentation or prior reconnaissance. Atlassian's recommendation of network restrictions and WAF rules as stopgaps suggests the company views immediate patching as the priority but recognizes many enterprises run these tools on-premises with slower update cycles, leaving a window of exposure.
- CVE-2026-21589 is a critical arbitrary file-access flaw affecting Atlassian Data Center products like Jira, Confluence and Bitbucket.
- Exploitation requires an attacker to already know the exact file name and path, limiting but not eliminating risk.
- Atlassian has issued patched versions and temporary mitigations (WAF rules, network restrictions) for admins who cannot patch immediately.
Source: bleepingcomputer.com, 2026-10-06
Published there as: “Atlassian warns of critical file-access flaw in Jira, Confluence”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.