Atlassian CVE-2026-21589: unauthenticated file read on 8 products
path traversal on self-hosted Data Center, no login required

Atlassian CVE-2026-21589: unauthenticated file read on 8 products

Atlassian disclosed CVE-2026-21589 on 5 October 2026. It is a path traversal, scored 9.3 by Atlassian on CVSS 4.0, in eight self-hosted products. An attacker who can reach the instance, and who already knows a file name and path, can read that file from the web application root. No login is required. Directory listing is not part of the bug.

What happened

The web application root is the folder that holds the product itself. In some configurations it can contain sensitive files. Atlassian says its affected cloud products are already patched and that its cloud investigation has not found exploitation. Bitbucket Cloud is not affected. Atlassian cannot confirm whether any self-hosted instance was hit.

The CVE record and some product tickets do not agree on every fixed build, including Crowd and Bamboo. Use the versions in the 6 October advisory, then confirm the build on the product ticket before you close the job.

Who is affected

Every version of these Data Center products before the fixed builds is in scope, including some end-of-life lines. Cloud customers do not need to act.

  • Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1
  • Confluence Data Center: 9.2.26, 10.2.19
  • Jira Software Data Center: 9.12.40, 10.3.26, 11.3.12
  • Jira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12
  • Bamboo Data Center: 10.2.24, 12.1.12
  • Crowd Data Center: 6.3.7, 7.0.3, 7.1.7, 7.2.4
  • Crucible and Fisheye: 4.9.15

What to do now

Upgrade internet-facing instances, or take them off the public network until the fixed build is on. A login page does not make the instance safe. Atlassian published temporary blocking rules for paths that contain a parent-directory sequence. Those rules are not a substitute for the patch. After the upgrade, decode access logs and look for the same pattern.

Source: The Hacker News, 6 October 2026. Critical Atlassian flaw lets unauthenticated attackers read known files across 8 products.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Cling botnet hides operator commands inside STUN traffic
Cling botnet STUN command channel on old router bugs