Atlassian Patches Critical Path Traversal Across 8 Products
CVE-2026-21589, CVSS 9.3: unauthenticated path traversal across eight Atlassian Data Center products. Patches released October 6, 2026.

Eight Atlassian Data Center products carry a critical path traversal, CVE-2026-21589 (CVSS 9.3). No authentication required. An attacker with network access to an exposed instance can read specific files from each product’s web application root directory. Patches released October 6, 2026.
Exploitation status: Atlassian reports no evidence of active exploitation in cloud products as of advisory publication. Self-hosted Data Center deployments are the affected surface; Atlassian-managed cloud instances are not.
If immediate patching is not possible, the vendor advisory documents temporary WAF and reverse proxy blocking rules for each product. For Confluence and Jira, the advisory also provides Tomcat and urlrewrite.xml rule-based mitigations.
Affected products and fixed versions
- Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1
- Confluence Data Center: 9.2.26, 10.2.19
- Jira Software Data Center: 9.12.40, 10.3.26, 11.3.12
- Jira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12
- Bamboo Data Center: 10.2.24, 12.1.12
- Crowd Data Center: 6.3.7, 7.0.3, 7.1.7, 7.2.4
- Crucible: 4.9.15
- Fisheye: 4.9.15
Previous Atlassian Data Center vulnerabilities, including CVE-2023-22515 and CVE-2022-26134, were adopted for ransomware intrusion campaigns after public disclosure. No exploitation is confirmed for CVE-2026-21589 as of publication.
- [ CRITICAL ]CVE-2026-21589Path traversal allows unauthenticated file read in eight Atlassian Data Center products
Found this useful? Share it.

