Skip to content
feed: live
0dayNews
atlassian
● Breaking

Atlassian Patches Critical Path Traversal Across 8 Products

CVE-2026-21589, CVSS 9.3: unauthenticated path traversal across eight Atlassian Data Center products. Patches released October 6, 2026.

Atlassian Patches Critical Path Traversal Across 8 Products
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Eight Atlassian Data Center products carry a critical path traversal, CVE-2026-21589 (CVSS 9.3). No authentication required. An attacker with network access to an exposed instance can read specific files from each product’s web application root directory. Patches released October 6, 2026.

Exploitation status: Atlassian reports no evidence of active exploitation in cloud products as of advisory publication. Self-hosted Data Center deployments are the affected surface; Atlassian-managed cloud instances are not.

If immediate patching is not possible, the vendor advisory documents temporary WAF and reverse proxy blocking rules for each product. For Confluence and Jira, the advisory also provides Tomcat and urlrewrite.xml rule-based mitigations.

Affected products and fixed versions

  • Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1
  • Confluence Data Center: 9.2.26, 10.2.19
  • Jira Software Data Center: 9.12.40, 10.3.26, 11.3.12
  • Jira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12
  • Bamboo Data Center: 10.2.24, 12.1.12
  • Crowd Data Center: 6.3.7, 7.0.3, 7.1.7, 7.2.4
  • Crucible: 4.9.15
  • Fisheye: 4.9.15

Previous Atlassian Data Center vulnerabilities, including CVE-2023-22515 and CVE-2022-26134, were adopted for ransomware intrusion campaigns after public disclosure. No exploitation is confirmed for CVE-2026-21589 as of publication.

Related CVEs
  • [ CRITICAL ]CVE-2026-21589Path traversal allows unauthenticated file read in eight Atlassian Data Center products

Found this useful? Share it.