Key Facts
- CVE: CVE-2026-21589
- CVSS: 9.3 Critical (CVSS 4.0)
- Exploited in the wild: Not reported as of October 6, 2026
- Fix available: Yes
- Last updated: October 6, 2026
What Is CVE-2026-21589?
CVE-2026-21589 is an Arbitrary File Read vulnerability in Atlassian Jira and Confluence (and other Data Center and Server Products) that lets a remote attacker who has not logged in retrieve certain files stored inside the application’s web root folder. The attacker needs to already know a target file’s precise name and location, since the vulnerability gives no way to browse or list the folder’s contents.
Atlassian says every version of eight self-hosted products, Bitbucket, Confluence, Jira Service Management, Jira, Bamboo, Crowd, Crucible, and Fisheye, carries this issue prior to the fixed releases, so the default installation of each is affected. Atlassian found and disclosed the issue itself and published fixed versions for every product on October 5, 2026. Atlassian Cloud versions of these products were already patched, so cloud customers do not need to act.
Organizations should prioritize affected and vulnerable internet-facing instances first, since Atlassian’s temporary mitigations do not fully replace patching. Deployments that keep sensitive files inside the web application’s root directory carry added risk until they are updated.
| CVE | Description | CVSS | Exploited in the wild |
|---|---|---|---|
| CVE-2026-21589 | Arbitrary File Access in Atlassian Data Center and Server Products | 9.3 Critical (CVSS 4.0) | Not reported |
Is CVE-2026-21589 Being Exploited?
As of October 6, 2026, no exploitation in the wild has been reported.
Timeline
- October 2, 2026: Atlassian attached the rewrite.config mitigation file to the public Jira ticket tracking this issue for Jira Data Center.
- October 5, 2026: Atlassian published its critical security advisory for CVE-2026-21589 covering eight self-hosted products, with fixed versions and mitigations, and the page was last modified the same day.
What Is Atlassian Data Center and Server Products?
Atlassian Jira and Confluence (and other Data Center and Server Products) are self-hosted versions of Atlassian’s collaboration and development tools, including Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye. Organizations run them on their own infrastructure to manage source code, documentation, service tickets, and project work, often storing internal files within the application.
Which Atlassian Data Center and Server Products Versions Are Affected?
| Product | Affected Versions | Fixed Version |
|---|---|---|
| Bitbucket Data Center | All versions are affected | 9.4.26, 10.2.8, 10.5.1 |
| Confluence Data Center | All versions are affected | 9.2.26, 10.2.19 |
| Jira Service Management Data Center | All versions are affected | 5.12.40, 10.3.26, 11.3.12 |
| Jira Software Data Center | All versions are affected | 9.12.40, 10.3.26, 11.3.12 |
| Bamboo Data Center | All versions are affected | 10.2.24, 12.1.12 |
| Crowd Data Center | All versions are affected | 6.3.7, 7.0.3, 7.1.7, 7.2.4 |
| Crucible | All versions are affected | 4.9.15 |
| Fisheye | All versions are affected | 4.9.15 |
Is Your Atlassian Data Center and Server Products Affected?
- An attacker needs network access to an affected instance, and no account or login is required to exploit the vulnerability.
- The attacker must already know the exact file name and path, since the vulnerability does not let them browse or list the web root directory.
- Deployments that store sensitive files inside the web application’s root directory face added risk until they are patched.
How to Fix CVE-2026-21589
Security teams should update every affected Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, or Fisheye Data Center instance to its fixed version as soon as possible. Where patching must wait, Atlassian recommends taking the instance off the public internet and applying its published interim mitigations until the update can be installed.
- Update each affected Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, or Fisheye Data Center instance to its listed fixed version.
- Restrict any instance that cannot be patched immediately from the public internet, even if it requires a login.
- Apply Atlassian’s published web application firewall regex rule to block path traversal patterns while awaiting the update.
- Enable the Tomcat RewriteValve or Bitbucket urlrewrite.xml mitigation on every cluster node, then restart each node.
- Review access logs for request paths containing two dots next to a slash, backslash, or double colon, decoding URLs up to twice.
- Ask security teams to check each instance for signs of compromise, since Atlassian cannot confirm impact per customer.
The vendor advisory has full details and any later changes.
How to Check for Compromise
Atlassian recommends reviewing web server access logs for request paths that contain two dots immediately next to a slash, backslash, or double colon, after decoding each URL up to twice. Atlassian says it cannot determine from its side whether a given instance was affected, so each organization’s security team should check its own logs for evidence of compromise.
How watchTowr Is Helping Clients
The watchTowr Platform delivers Preemptive Exposure Management, identifying, validating, and mitigating external exposure across enterprise environments.
- Rapid Reaction identified exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act.
- Active Defense released targeted network-level mitigations to clients, enabling immediate risk reduction while permanent fixes are applied.
Request a demo to see how Rapid Reaction identifies exposure to emerging threats like CVE-2026-21589.
