Atlassian patches critical flaw letting attackers read files on self-hosted Data Centre products
Atlassian has fixed a critical vulnerability, tracked as CVE-2026-21589, that allows attackers without a login to read files from the web application root of eight self-hosted products. The affected products are Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd Data Center, plus the Crucible and Fisheye code review tools. Every version before the fixed releases is vulnerable. Atlassian rated the bug 9.3 out of 10.0 on the CVSS 4.0 scale, noting this was its own assessment and customers should judge the impact in their own environments.
Exploitation has one hurdle: an attacker must know the exact name and path of the target file, and the flaw cannot list directory contents. However, Atlassian products install to well-documented default locations, and the company warned that some configurations could leave sensitive files exposed. Cloud customers need to do nothing, as Atlassian has patched its Cloud products and found no evidence of exploitation there. Fixed releases include Confluence 9.2.26 and 10.2.19, Jira Software 9.12.40, 10.3.26 and 11.3.12, and Bitbucket 9.4.26, 10.2.8 and 10.5.1.
For those unable to patch immediately, Atlassian first recommends taking internet-facing instances offline. Failing that, it offers stopgaps such as a web application firewall rule, a Tomcat RewriteValve configuration, or a urlrewrite.xml rule for Bitbucket. These block directory traversal patterns. Teams should also search access logs for those patterns, decoding requests up to twice, because attackers often double-encode characters to evade filters. Past Confluence flaws, CVE-2022-26134 and CVE-2023-22515, were exploited in the wild soon after disclosure.