Atlassian patches critical file-access flaw across eight self-hosted products
Atlassian has issued fixes for CVE-2026-21589, a critical vulnerability in eight self-hosted Data Center products, including Jira, Confluence and Bitbucket. An unauthenticated attacker can read specific files in an application’s web root, but must know each file’s exact path; Atlassian rates the flaw 9.3 out of 10. Cloud products have been patched, with no customer action required.
Bottom line — Atlassian says self-hosted customers should patch each affected product or restrict access until they can.
Go deeper 5
-
Atlassian says the flaw affects all versions before the relevant fixed releases and warns that some configurations may store sensitive files in the web root.
-
The vulnerability does not let attackers list directory contents, according to Atlassian.
-
For installations that cannot be patched immediately, Atlassian recommends restricting external access; temporary WAF or server-level rules are also available.
-
Atlassian advises security teams to review access logs for traversal patterns, decoding requests up to twice to catch encoded variants.
-
BleepingComputer reports Atlassian has no evidence that the flaw is being exploited, but cannot confirm whether individual customer instances have been affected.