Atlassian has disclosed CVE-2026-21589, a critical arbitrary file access vulnerability affecting Confluence Data Center and seven other self-managed products. The advisory, published on October 5, 2026, warns that every version of the affected software is exposed and urges administrators to act right away, either by upgrading or by putting temporary safeguards in place.
Beyond Confluence Data Center, the flaw reaches Bitbucket Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. Atlassian is tracking the issue under BSERV-20604, CONFSERVER-104488, JSDSERVER-16809, JRASERVER-79546, BAM-26567, CWD-6610, CRUC-8741 and FE-7583.
The bug lets an attacker with no login read specific files inside the web application’s root directory. There is a catch for attackers: they must already know a file’s exact name and location, since the weakness does not reveal or list directory contents. Even so, Atlassian notes that some setups may store sensitive files there, which raises the stakes.
Atlassian scores CVE-2026-21589 at 9.3, placing it in the Critical band, using the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H. The company describes this as its own internal assessment and advises organizations to judge how it applies to their environments.
Cloud users are not affected. Atlassian says its Cloud products have already been patched, its investigation found no sign of exploitation there, and Cloud customers need to take no action.
The primary fix is an upgrade. Atlassian recommends moving each installation to a fixed release, ideally the fixed LTS version or the newest available build.
| Product | Fixed versions |
| Bitbucket Data Center | 9.4.26, 10.2.8, 10.5.1 |
| Confluence Data Center | 9.2.26, 10.2.19 |
| Jira Service Management Data Center | 5.12.40, 10.3.26, 11.3.12 |
| Jira Software Data Center | 9.12.40, 10.3.26, 11.3.12 |
| Bamboo Data Center | 10.2.24, 12.1.12 |
| Crowd Data Center | 6.3.7, 7.0.3, 7.1.7, 7.2.4 |
| Crucible | 4.9.15 |
| Fisheye | 4.9.15 |
Teams that cannot upgrade yet should take instances offline from the internet where possible, including those protected by user authentication. Atlassian then offers three mitigations, all built on one regex meant to block “..” sitting directly next to /, , or ::, including URL-encoded forms:
(?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).*
Atlassian says it cannot confirm whether any customer instance has been hit and advises bringing in local security teams. Investigators can URL-decode each access-log request up to twice and search for “..” next to /, , or ::, or run the regex directly against raw log lines.
Under Atlassian’s security bug fix policy, critical fixes are backported as new maintenance releases instead of binary patches. Customers can subscribe to alert emails at my.atlassian.com/email and raise questions through support.atlassian.com.