Atlassian Warns 8 Data Center Products Face 9.3 File-Access Flaw
Updated
Updated · InfoWorld · Oct 7
Atlassian Warns 8 Data Center Products Face 9.3 File-Access Flaw
3 articles · Updated · InfoWorld · Oct 7
Summary
CVE-2026-21589 lets unauthenticated attackers read files from web application root directories in all versions of eight Atlassian data center products, prompting the company to urge immediate upgrades to fixed releases.
Atlassian said the flaw requires no login or user interaction and, in some configurations, path traversal could expose sensitive files that help attackers pivot into broader attacks on connected systems.
The affected lineup includes Bamboo, Bitbucket, Confluence, Crowd, Crucible, Fisheye, Jira Service Management and Jira Software; cloud offerings are already patched, and Atlassian said it has found no evidence of cloud exploitation.
Customers that cannot patch immediately were told to remove exposed instances from the internet or apply WAF, Tomcat RewriteValve or Bitbucket urlrewrite mitigations, though Atlassian said those are limited stopgaps rather than replacements for patching.
Atlassian also advised security teams to review logs for compromise and rotate credentials, tokens and keys if exposure is suspected, underscoring that the main risk is not file reading itself but the secrets those files may contain.