Particle.news

Atlassian Data Center Flaw Lets Unauthenticated Actors Read Known Files

Atlassian published fixes and cloud patches and says self-hosted operators must upgrade or deploy temporary blocking rules to protect internet-exposed instances.

Overview

  • Atlassian disclosed the arbitrary file-access flaw tracked as CVE-2026-21589 on Monday and assigned it a 9.3 CVSS 4.0 score.
  • The bug affects eight Data Center products — Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye — and Atlassian published fixed versions for each product.
  • Exploitation lets an unauthenticated attacker read a specific file in the web application root only if the attacker knows the exact file name and path and cannot list directory contents.
  • Atlassian says its cloud offerings were automatically patched and show no evidence of exploitation but cannot confirm whether self-hosted instances were compromised, so operators should search raw access logs for encoded '..' traversal patterns and check for signs of access.
  • If operators cannot patch immediately they should restrict or take internet-exposed instances offline and apply Atlassian’s temporary mitigations — WAF/reverse-proxy rules, Tomcat RewriteValve rules, or a Bitbucket urlrewrite.xml rule — making sure the rules are installed on every node and restarted where required.