Protect.Computer
NEWS

Atlassian Critical Flaw CVE-2026-21589 Hits 8 Products

· 1 min read · Network safety
Atlassian Critical Flaw CVE-2026-21589 Hits 8 Products

Atlassian has disclosed CVE-2026-21589, a critical path-traversal flaw rated 9.3 out of 10 that affects eight of its self-hosted products. An attacker with no login can read specific files in each product’s web application root directory, the folder on the server that holds the web application itself. The attacker must already know a file’s exact name and path and cannot list what the directory holds, but in some configurations the folder can contain sensitive files, which raises the risk, according to Atlassian. Atlassian’s cloud products have already been patched, and cloud customers need to take no action.

Atlassian advises customers who cannot upgrade all at once to take the instance offline if possible. Any instance reachable from the public internet, even one that requires a login, should be restricted from outside access until it is upgraded or a temporary blocking rule is in place. Those rules block requests whose URL contains .. directly next to /, \ or ::, including URL-encoded forms, and can be applied at a web application firewall or reverse proxy for all eight products; Atlassian says they are limited and not a replacement for patching.

How to check if you’re affected

Affected products are the Data Center editions of Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd, plus Crucible and Fisheye. All versions before the fixed versions are affected, including versions that have reached end of life. Atlassian listed these fixed versions as of October 6:

  • Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1
  • Confluence Data Center: 9.2.26, 10.2.19
  • Jira Software Data Center: 9.12.40, 10.3.26, 11.3.12
  • Jira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12
  • Bamboo Data Center: 10.2.24, 12.1.12
  • Crowd Data Center: 6.3.7, 7.0.3, 7.1.7, 7.2.4
  • Crucible and Fisheye: 4.9.15

The CVE record also lists the older Server editions of several of these products as affected with no fixed versions, and some version numbers in the record differ from the advisory, so confirm against Atlassian’s advisory for your product.

Sources

Related reading