Proactive Threat Intelligence from the team that finds the vulnerabilities. We publish what is being exploited right now, who is doing it, and whether it reaches you. No vendor summaries written a week late.

Atlassian Jira, Confluence (and more) Arbitrary File Read Vulnerability (CVE-2026-21589)

CVE-2026-21589 is an Arbitrary File Read vulnerability in Atlassian Jira and Confluence (and other Data Center and Server Products) that lets an attacker without a login read specific files on the server. Patch now or apply Atlassian's interim mitigations.

Key Facts

  • CVE: CVE-2026-21589
  • CVSS: 9.3 Critical (CVSS 4.0)
  • Exploited in the wild: Not reported as of October 6, 2026
  • Fix available: Yes
  • Last updated: October 6, 2026

What Is CVE-2026-21589?

CVE-2026-21589 is an Arbitrary File Read vulnerability in Atlassian Jira and Confluence (and other Data Center and Server Products) that lets a remote attacker who has not logged in retrieve certain files stored inside the application’s web root folder. The attacker needs to already know a target file’s precise name and location, since the vulnerability gives no way to browse or list the folder’s contents.

Atlassian says every version of eight self-hosted products, Bitbucket, Confluence, Jira Service Management, Jira, Bamboo, Crowd, Crucible, and Fisheye, carries this issue prior to the fixed releases, so the default installation of each is affected. Atlassian found and disclosed the issue itself and published fixed versions for every product on October 5, 2026. Atlassian Cloud versions of these products were already patched, so cloud customers do not need to act.

Organizations should prioritize affected and vulnerable internet-facing instances first, since Atlassian’s temporary mitigations do not fully replace patching. Deployments that keep sensitive files inside the web application’s root directory carry added risk until they are updated.

CVEDescriptionCVSSExploited in the wild
CVE-2026-21589Arbitrary File Access in Atlassian Data Center and Server Products9.3 Critical (CVSS 4.0)Not reported

Is CVE-2026-21589 Being Exploited?

As of October 6, 2026, no exploitation in the wild has been reported.

Timeline

  • October 2, 2026: Atlassian attached the rewrite.config mitigation file to the public Jira ticket tracking this issue for Jira Data Center.
  • October 5, 2026: Atlassian published its critical security advisory for CVE-2026-21589 covering eight self-hosted products, with fixed versions and mitigations, and the page was last modified the same day.

What Is Atlassian Data Center and Server Products?

Atlassian Jira and Confluence (and other Data Center and Server Products) are self-hosted versions of Atlassian’s collaboration and development tools, including Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye. Organizations run them on their own infrastructure to manage source code, documentation, service tickets, and project work, often storing internal files within the application.

Which Atlassian Data Center and Server Products Versions Are Affected?

ProductAffected VersionsFixed Version
Bitbucket Data CenterAll versions are affected9.4.26, 10.2.8, 10.5.1
Confluence Data CenterAll versions are affected9.2.26, 10.2.19
Jira Service Management Data CenterAll versions are affected5.12.40, 10.3.26, 11.3.12
Jira Software Data CenterAll versions are affected9.12.40, 10.3.26, 11.3.12
Bamboo Data CenterAll versions are affected10.2.24, 12.1.12
Crowd Data CenterAll versions are affected6.3.7, 7.0.3, 7.1.7, 7.2.4
CrucibleAll versions are affected4.9.15
FisheyeAll versions are affected4.9.15

Is Your Atlassian Data Center and Server Products Affected?

  • An attacker needs network access to an affected instance, and no account or login is required to exploit the vulnerability.
  • The attacker must already know the exact file name and path, since the vulnerability does not let them browse or list the web root directory.
  • Deployments that store sensitive files inside the web application’s root directory face added risk until they are patched.

How to Fix CVE-2026-21589

Security teams should update every affected Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, or Fisheye Data Center instance to its fixed version as soon as possible. Where patching must wait, Atlassian recommends taking the instance off the public internet and applying its published interim mitigations until the update can be installed.

  1. Update each affected Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, or Fisheye Data Center instance to its listed fixed version.
  2. Restrict any instance that cannot be patched immediately from the public internet, even if it requires a login.
  3. Apply Atlassian’s published web application firewall regex rule to block path traversal patterns while awaiting the update.
  4. Enable the Tomcat RewriteValve or Bitbucket urlrewrite.xml mitigation on every cluster node, then restart each node.
  5. Review access logs for request paths containing two dots next to a slash, backslash, or double colon, decoding URLs up to twice.
  6. Ask security teams to check each instance for signs of compromise, since Atlassian cannot confirm impact per customer.

The vendor advisory has full details and any later changes.

How to Check for Compromise

Atlassian recommends reviewing web server access logs for request paths that contain two dots immediately next to a slash, backslash, or double colon, after decoding each URL up to twice. Atlassian says it cannot determine from its side whether a given instance was affected, so each organization’s security team should check its own logs for evidence of compromise.

How watchTowr Is Helping Clients

The watchTowr Platform delivers Preemptive Exposure Management, identifying, validating, and mitigating external exposure across enterprise environments.

  • Rapid Reaction identified exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act.
  • Active Defense released targeted network-level mitigations to clients, enabling immediate risk reduction while permanent fixes are applied.

Request a demo to see how Rapid Reaction identifies exposure to emerging threats like CVE-2026-21589.


If you are a watchTowr client

Want to know if this reaches you, before the next one?

watchTowr validates exposure and mitigates at the edge in under an hour.

On this page
Attackers Don't Give Up. Neither Should Your Security Testing.

Zero install. No infrastructure changes. Uplift your security posture within hours of onboarding the watchTowr Platform.

Find Out What an Attacker Can Reach Before They Do.

Point us at a domain. We reconstruct your real external estate and come back with validated exposure, not a theoretical CVE list.

Disclosure to Exploitation Is Four Hours. Patching Is Not.

The watchTowr Platform validates your exposure to an emerging threat and mitigates it at the edge while the vendor patch is still in testing.

We Find the Vulnerabilities. You Hear It From Us First.

watchTowr Labs publishes what is being exploited right now and whether it touches your estate, not vendor summaries written a week late.

Your Exposure Changes Weekly. Annual Testing Cannot Describe It.

Continuous, fully external validation of what an attacker can actually exploit against your estate, at a 0.01% false-positive rate.

See the Estate You Own, Including What No Asset List Holds.

Subsidiaries, forgotten infrastructure, shadow IT. We rebuild your external surface from a single domain, then validate what is exposed.