Critical Atlassian File Access Flaw Draws Attacks Across Eight Products

CVE-2026-21589 is being exploited after a public PoC, putting self-hosted Jira, Confluence, Bitbucket and other Atlassian products at risk.

Written By
Kezia Jungco
Kezia Jungco
Oct 7, 2026
3 minute read
Laptop displaying the blue Atlassian logo and company name on a white screen.

A critical Atlassian flaw is being exploited across Jira, Confluence, Bitbucket, and other products. Image: William Liu/Unsplash

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Attackers have started probing a critical Atlassian vulnerability that can expose files from self-hosted deployments without requiring authentication. The flaw affects eight products, including Jira, Confluence, and Bitbucket.

Tracked as CVE-2026-21589 and rated 9.3 out of 10 by Atlassian, the file-access vulnerability lets an attacker retrieve files from an affected application’s web root if the exact file name and path are known. Atlassian initially reported no evidence of exploitation, but attack attempts appeared within hours of researchers publishing technical details and a public proof-of-concept (PoC). Atlassian disclosed the flaw on Oct. 5. Affected Cloud products have already been patched, but administrators of vulnerable self-hosted installations should patch immediately or apply Atlassian’s temporary mitigations.

Exploitation attempts followed public PoC

The Hacker News reported that CVE-2026-21589 affects Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Attackers cannot enumerate directory contents, but known paths can still let them access sensitive files without authentication.

Atlassian initially said its investigation had found no evidence of exploitation. BleepingComputer said that the company was urging administrators to update immediately or restrict external network access if patching was not yet possible.

The situation changed quickly. BleepingComputer also noted that security company Previdian began detecting exploitation attempts on its honeypot network within two hours of watchTowr publishing technical research and a public PoC. watchTowr also released a public tool to check Jira, Confluence, and Bitbucket instances for the vulnerability.

Eight Atlassian products require updates

Atlassian said all versions released before the listed fixes are vulnerable and recommends upgrading to a fixed LTS version or later.

Product

Fixed versions

Bitbucket Data Center

9.4.26, 10.2.8, 10.5.1

Confluence Data Center

9.2.26, 10.2.19

Jira Service Management Data Center

5.12.40, 10.3.26, 11.3.12

Jira Software Data Center

9.12.40, 10.3.26, 11.3.12

Bamboo Data Center

10.2.24, 12.1.12

Crowd Data Center

6.3.7, 7.0.3, 7.1.7, 7.2.4

Crucible

4.9.15

Fisheye

4.9.15

Affected Atlassian Cloud products have already been patched, and no action is required from Cloud customers.

Advertisement

Stolen credentials could lead to deeper access

Yordan Ganchev, principal threat intelligence specialist at watchTowr, warned that the file-read vulnerability could give attackers information needed to move further into a victim’s environment.

“It allows unauthenticated attackers to retrieve sensitive files within the webroot directory through a single request and extract tokens, credentials, keys or other authentication material that can be used by attackers to further breach the victim organization,” Ganchev said.

He flagged organizations using Crowd for single sign-on as particularly exposed.

“Organizations that have SSO enabled through Crowd, which is the recommended approach, should be extra cautious,” Ganchev said.

watchTowr demonstrated that a Jira deployment integrated with Crowd can store its Crowd application name and plaintext application password in a predictable configuration file within the web root.

If attackers retrieve those credentials and can reach Crowd’s user-management endpoints with sufficient permissions, they could create users and add them to administrator groups. Crowd’s IP restrictions can limit this attack chain.

Admins should patch immediately

“Organizations running any of the 8 affected Atlassian products on-site should patch immediately,” Ganchev said.

If patching is not immediately possible, he advised organizations to follow Atlassian’s guidance and deploy WAF rules to block exploitation attempts.

Atlassian also recommends restricting external access where possible and provides WAF, proxy, Tomcat RewriteValve, and URL rewrite mitigations for affected products. Administrators should review access logs for the traversal patterns described in the advisory.

With exploitation attempts already observed and automated scanning now available, internet-facing Atlassian deployments should be treated as a priority for remediation.

Also read: Fake AI marketing sites impersonating ChatGPT, Gemini, Claude, and Muse are using live phishing flows to steal logins, ad-account credentials, and MFA codes.


Kezia Jungco

Kezia Jungco is a staff writer with five years of hands-on experience testing and analyzing generative AI platforms, chatbots, and NLP tools. She writes in-depth coverage for both enterprise and consumer audiences, focusing on artificial intelligence, data analytics, CRM solutions, cloud infrastructure, cybersecurity, and emerging tech trends. Her work appears in TechRepublic, eWEEK, Datamation, TechnologyAdvice, and Selling Signals.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.