Atlassian Patches Critical Flaw Affecting Jira, Confluence, and Other Products

CVE-2026-21589, a path traversal flaw scoring 9.3, affects all versions of Jira, Confluence, Bitbucket, Bamboo, and five other Atlassian products.

Published on Oct 7, 2026
Ingrid Fadelli Written by Ingrid Fadelli
Atlassian Patches Critical Flaw Affecting Jira, Confluence and Other Products

Software company Atlassian has released security updates addressing a critical flaw that could allow unauthenticated attackers to access files stored within vulnerable applications. The flaw affects all versions of Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, and Crowd Data Center, as well as Crucible and Fisheye.

The vulnerability is tracked as CVE-2026-21589 and received a CVSS severity score of 9.3. In a security advisory published on Oct. 5, Atlassian urged affected customers to install available fixes immediately.

“This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions,” the company said.

CVE-2026-21589 stems from a path traversal weakness, which can allow specially crafted file paths to bypass restrictions intended to prevent access to specific files.

To exploit the vulnerability, attackers need to know the exact name and path of the file they are trying to access. Yet Atlassian warned that some configurations could leave sensitive files within affected directories, increasing the potential impact of successful exploitation.

Researchers Demonstrate Access to Sensitive Credentials

Security researchers at watchTowr Labs analyzed the flaw following Atlassian’s disclosure and successfully exploited it in a test environment.

They also identified a potentially more serious scenario in instances where Jira is integrated with Atlassian Crowd, a centralized identity management and single sign-on platform. Atlassian’s documented configuration for this integration can store an application name and password in plaintext within a file called crowd.properties.

In its test environment, watchTowr accessed this file by exploiting CVE-2026-21589, then used the exposed credentials to access Crowd, create new users and modify user privileges. The researchers noted that Crowd can restrict access to specific IP addresses, potentially making this attack scenario considerably more difficult.

watchTowr published the full technical details of its attack chain, along with a tool organizations can use to check whether their instances are vulnerable.

Customers Urged to Patch Their Systems

Atlassian has found no evidence of exploitation in its Cloud products so far. Nonetheless, it is urging organizations to install the available updates as soon as possible. Fixed versions include Jira Software 9.12.40, 10.3.26, and 11.3.12, Confluence 9.2.26 and 10.2.19, and Bitbucket 9.4.26, 10.2.8, and 10.5.1, with the full list in Atlassian’s advisory.

Affected Cloud products have already been patched, so Cloud customers do not need to take action.

Atlassian advised customers unable to update immediately to temporarily remove affected internet-facing instances from the public internet. Atlassian also provided temporary mitigation options and advised organizations to examine access logs for affected systems for evidence of compromise.

“Atlassian cannot confirm if your instances have been affected by this vulnerability,” the company warned. “You should engage your local security team to check all affected instances for evidence of compromise.”

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Ingrid Fadelli
Ingrid Fadelli Contributing Reporter

Ingrid Fadelli is a freelance journalist with a BSc in Psychology and an MA in International Journalism, both from City University London. For the past 10 years, she has been writing articles focusing on research and emerging technologies in various fields, including AI, robotics, electronics engineering, cybersecurity, neuroscience, biology, physics and environmental science. She published articles in Phys.org, TechXplore, MedicalXpress, Scientia, E&T Magazine, and on various other media, translating complex scientific developments into engaging stories for broad audiences.