Atlassian on Monday released fixes for a critical vulnerability that lets unauthenticated attackers read files from eight of its self-hosted Data Centre products.
Tracked as CVE-2026-21589 and rated 9.3 under CVSS 4.0, the flaw affects Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd Data Centre, Crucible, and Fisheye. Atlassian says every version before the fixed releases is vulnerable, including those past the end of life. The score comes from the company’s own assessment.
The bug is a path traversal, according to the CVE record Atlassian filed. An attacker sends a URL containing a crafted “..” sequence, which steps outside the folder the application is meant to serve. The server then returns a file from the web application root, the directory that holds the application itself, and no login is needed.
The attack has limits. The attacker must already know the file’s exact name and path, and the flaw cannot list directory contents. Atlassian warns that some configurations leave sensitive files in that directory, which raises the risk, but it does not say which files or which setups.
The flawed code has been in the products for years. The CVE record traces it back to Jira Software 7.1.0, Confluence 5.10.0, Bitbucket 4.6.0, Crowd 2.11.0, Jira Service Management 3.1.0 and Bamboo 7.0.1.
The fixed builds are:
- Bitbucket 9.4.26, 10.2.8 and 10.5.1
- Confluence 9.2.26 and 10.2.19
- Jira Software 9.12.40, 10.3.26 and 11.3.12
- Jira Service Management 5.12.40, 10.3.26 and 11.3.12
- Bamboo 10.2.24 and 12.1.12
- Crowd 6.3.7, 7.0.3, 7.1.7 and 7.2.4
- Crucible and Fisheye 4.9.15
Atlassian no longer ships binary patches, so these are full maintenance releases.
The CVE record lists more affected products than the advisory does. It marks every version of Bamboo Server, Bitbucket Server, Confluence Server and Crowd Server, Atlassian’s older self-hosted line, as affected, with no fix listed. The record also lists Crowd as patched at 7.1.1, while the advisory lists 7.1.7, and one Bamboo field reads 10.2.4 rather than 10.2.24.
Atlassian said it has patched its affected Cloud products, has found no evidence of exploitation, and requires no action from Cloud customers. It offers no such assurance for self-hosted deployments. “Atlassian cannot confirm if your instances have been affected by this vulnerability,” the company said.
The scoring raises questions Atlassian has not answered. The CVSS vector rates the integrity impact on the vulnerable product as none, yet rates the confidentiality, integrity, and availability impacts on other systems as high. The CVE record also labels the weakness as arbitrary read and write, while the advisory describes only file access.
Atlassian tells admins who cannot upgrade right away to take their instances offline, including those behind a login. It also published three temporary rules that block URLs with “..” next to /, \ or ::, including URL-encoded forms:
- A web application firewall or reverse-proxy rule, which works for all eight products. It is the only option for Crucible and Fisheye.
- A Tomcat RewriteValve rule for Confluence, Jira, Jira Service Management, Bamboo and Crowd. Each node has to be shut down, changed and restarted.
- A urlrewrite.xml rule for Bitbucket, which must also go on every mirror and mirror farm node.
The Jira ticket calls these workarounds limited and no replacement for patching. The rewrite.config files attached to the Jira and Crowd tickets show October 2 upload dates, three days before the advisory went out.
To look for past attacks, Atlassian advises two methods. Admins can URL-decode each access-log request line up to twice and look for “..” beside /, \ or ::. Or they can run the blocking regex over raw log lines. The advisory does not explain how to tell a failed probe from a request that returned a file.
Path traversal in Atlassian software has been exploited before. CISA added CVE-2021-26086, a file-read flaw in Jira Server and Data Centre, to its Known Exploited Vulnerabilities catalogue on November 12, 2024.
Community Discussion
Join the conversation. Ask questions, share solutions, and help others.
Be the first to start the discussion!
