Critical Vulnerability in Atlassian Data Center Products
7 October 2026
Attackers can exploit a critical vulnerability in multiple Atlassian Data Center products to gain unauthorised access to sensitive files without authentication. Patch immediately.
Background
Atlassian has released security updates to address a vulnerability (CVE-2026-21589) affecting Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye Data Center products. This vulnerability has a Common Vulnerability Scoring System (CVSS v4.0) score of 9.3 out of 10.
Impact
Due to a path traversal vulnerability in multiple Atlassian Data Center products, an unauthenticated remote attacker could access specific files within the web application root directory of the affected system, potentially exposing sensitive configuration files, credentials, and tokens that could enable further attacks.
Affected Products
All versions of the following Atlassian Data Center and Server products prior to the fixed versions are affected:
Bitbucket Data Center and Server
Confluence Data Center and Server
Jira Software Data Center and Server
Jira Service Management Data Center and Server
Bamboo Data Center and Server
Crowd Data Center and Server
Crucible
Fisheye
Please refer to Atlassian's official security advisory for the specific fixed versions for each product.
Recommendations
Users and administrators of affected self-hosted products are advised to update to the fixed versions or latest version for each affected product immediately. No action is required for Atlassian Cloud customers as the fix has already been applied.
References
https://nvd.nist.gov/vuln/detail/CVE-2026-21589 (opens in new tab)
