Security News

Atlassian urges Data Center customers to patch critical file access flaw

The Register · 6 Oct 2026
Key Takeaway If you run self-hosted Atlassian Data Center products, apply the update as soon as possible, and until then restrict internet access to those systems.

Atlassian has sent customers an email marked "Action required", asking them to update their self-hosted Data Center products. The issue is tracked as CVE-2026-21589 and is rated 9.3, which is critical. It affects the Data Center versions of Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible and Fisheye.

According to Atlassian, the flaw allows an unauthenticated attacker to access specific files within the web application root directory. The company warns that in some configurations, sensitive files may be present, which raises the risk. There is some reassurance: attackers must know the exact filename and path, and the flaw does not let them list the contents of a directory. Fixed versions have been released, so customers mainly need to schedule a change window to upgrade.

For those who cannot patch straight away, Atlassian advises removing instances from the internet where possible. It says instances reachable from the public internet, including those requiring user login, should have external network access restricted until the fix is applied. Its advisory also includes further mitigations and guidance on checking whether an instance needs the update. Customers using Atlassian's cloud service do not need to act, as Atlassian has already fixed the issue in its own hosted offering.

Atlassian CVE-2026-21589 Patch Management Vulnerability

Summarised by CISO AI from The Register, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.