Path traversal allows unauthenticated file read in eight Atlassian Data Center products
CVSS 9.3 path traversal lets unauthenticated attackers read files from eight Atlassian Data Center products' web root directories. Patches released October 6, 2026.
- Vendor
- Atlassian
- Product
- Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, Fisheye Data Center
- CVSS
- 9.3
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
CVE-2026-21589 is a path traversal vulnerability in eight Atlassian Data Center products. An unauthenticated attacker with network access can read specific files from each product’s web application root directory without any prior authentication.
Atlassian released patched versions on October 6, 2026. The company reports no evidence of exploitation in cloud-hosted products. Self-hosted Data Center deployments are the affected surface.
Affected products and fixed versions:
- Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1
- Confluence Data Center: 9.2.26, 10.2.19
- Jira Software Data Center: 9.12.40, 10.3.26, 11.3.12
- Jira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12
- Bamboo Data Center: 10.2.24, 12.1.12
- Crowd Data Center: 6.3.7, 7.0.3, 7.1.7, 7.2.4
- Crucible: 4.9.15
- Fisheye: 4.9.15
For environments that cannot patch immediately, the vendor advisory includes WAF and reverse proxy blocking rules, plus Tomcat and urlrewrite.xml mitigations for Confluence and Jira.
