Overview
- Atlassian disclosed the arbitrary file-access flaw tracked as CVE-2026-21589 on Monday and assigned it a 9.3 CVSS 4.0 score.
- The bug affects eight Data Center products — Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye — and Atlassian published fixed versions for each product.
- Exploitation lets an unauthenticated attacker read a specific file in the web application root only if the attacker knows the exact file name and path and cannot list directory contents.
- Atlassian says its cloud offerings were automatically patched and show no evidence of exploitation but cannot confirm whether self-hosted instances were compromised, so operators should search raw access logs for encoded '..' traversal patterns and check for signs of access.
- If operators cannot patch immediately they should restrict or take internet-exposed instances offline and apply Atlassian’s temporary mitigations — WAF/reverse-proxy rules, Tomcat RewriteValve rules, or a Bitbucket urlrewrite.xml rule — making sure the rules are installed on every node and restarted where required.