Atlassian has published an advisory for CVE-2026-21589, an arbitrary file access flaw it rates Critical at CVSS 9.3. Every version of eight self-hosted products is affected: Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd Data Center, plus Crucible and Fisheye.

According to Atlassian’s advisory, released Oct. 5, an unauthenticated attacker can read specific files inside the web application root directory. Exploitation requires prior knowledge of the target file’s exact name and path, and the flaw does not let an attacker list directory contents. Atlassian Cloud products have already been patched, the company says its investigation found no evidence of exploitation, and Cloud customers need to do nothing.

Atlassian tells Data Center customers to patch immediately. The advisory lists fixed builds for each product, for example Confluence Data Center 9.2.26 or 10.2.19, Jira Software Data Center 9.12.40, 10.3.26 or 11.3.12, and Crucible and Fisheye 4.9.15. Where patching has to wait, Atlassian says to take the instance off the internet if possible. It also offers two stopgaps: a web application firewall or proxy rule that blocks “..” sequences next to slashes, or, for Confluence, Jira, Jira Service Management, Bamboo and Crowd, a rewrite rule in Tomcat. The advisory also describes access-log searches for requests carrying those sequences.

One flaw across eight products means a single advisory reaches every team that runs Jira, Confluence or Bitbucket, and those teams are often different people. The first task is an inventory of every Data Center node, including Crowd, Crucible and Fisheye, which are easy to miss in a list built around Jira and Confluence.

Our read: a firewall rule is a hold, not a fix. It protects only traffic that passes through the firewall, and attackers have walked around such rules before, as in PeopleSoft Attackers Walked Around the WAF Rules. Settle which instances are reachable from the internet first, then patch in that order, an approach argued in Start the Patch Clock on Release Day, Not Advisory Day.

Source: Atlassian security advisory: CVE-2026-21589 Arbitrary File Access Vulnerability impacts Multiple Products