NEWS
Atlassian’s 9.3 File-Read Bug Repeats a 2021 Exploited Flaw
CVE-2026-21589 scores 9.3 across eight Atlassian Data Center products, echoing a 2021 Jira file-read later listed as exploited.
Atlassian scored CVE-2026-21589 a 9.3 on October 5, 2026, across eight self-hosted Data Center products. An attacker with no login can read a file in the web application root if they already know its exact path.
The last time Jira exposed files this way, the U.S. Cybersecurity and Infrastructure Security Agency later put that older bug on its exploited list. This one is wider, and the leftover Server fleet has no vendor build to install.
A 2021 Jira File Read Later Made CISA’s Exploited List
On August 16, 2021, Atlassian published CVE-2021-26086. The National Vulnerability Database still describes it as a path traversal in the /WEB-INF/web.xml endpoint on Jira Server and Data Center, scored 5.3, which let a remote attacker read particular files. Public proof-of-concept code was in Exploit-DB by October 6, 2021, 51 days later.
CISA added that Jira bug to its catalog of known exploited vulnerabilities on November 12, 2024, more than three years after disclosure, and gave federal agencies until December 3, 2024, to apply vendor mitigations or stop using the product. The “must already know the file name” limit did not keep it off that list.
THE LAST TIME FILES CAME OUT OF JIRA
- August 16, 2021: Atlassian publishes CVE-2021-26086, a path traversal that reads particular files through /WEB-INF/web.xml on Jira Server and Data Center.
- October 6, 2021: A public exploit for Jira Server and Data Center 8.16.0 is listed in Exploit-DB.
- November 12, 2024: CISA adds the bug to its exploited catalog and sets a December 3, 2024 deadline.
- October 5, 2026: Atlassian publishes CVE-2026-21589, an unauthenticated file read across eight self-hosted products, scored 9.3.
The new bug is the same class of request: a path that climbs into the web application root, which is the folder that holds the app itself. Atlassian says the attacker cannot list that folder, and must already know the exact name and path. In some setups, it says, sensitive files sit there and raise the risk. It does not name those files, and it does not explain the high marks it gave for harm to other systems.
Which Atlassian Products Does CVE-2026-21589 Affect?
The October 5 advisory names Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. All versions before the listed fixes are in scope, including releases that have already reached end of life. Atlassian tells customers to move to a fixed long-term support release or later, and it published fixed versions for each product rather than a binary hot patch.
The company rates the flaw Critical at 9.3 under CVSS 4.0, with the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H. That scoring says the bug is reachable over the network with no login and no user click, that confidentiality on the vulnerable host is high, that integrity and availability on that host are none, and that confidentiality, integrity, and availability on subsequent systems are all high. Atlassian tells customers to judge how that applies to their own setup.
FIXED VERSIONS IN THE OCTOBER 5 ADVISORY
| Product | Fixed versions |
|---|---|
| Bitbucket Data Center | 9.4.26, 10.2.8, 10.5.1 |
| Confluence Data Center | 9.2.26, 10.2.19 |
| Jira Software Data Center | 9.12.40, 10.3.26, 11.3.12 |
| Jira Service Management Data Center | 5.12.40, 10.3.26, 11.3.12 |
| Bamboo Data Center | 10.2.24, 12.1.12 |
| Crowd Data Center | 6.3.7, 7.0.3, 7.1.7, 7.2.4 |
| Crucible | 4.9.15 |
| Fisheye | 4.9.15 |
The CVE record Atlassian filed goes further back than those patch lines. It says the flaw was introduced in Confluence 5.10.0, in Bitbucket 4.6.0, in Jira Software 7.1.0, in Jira Service Management 3.1.0, in Crowd 2.11.0, and in Bamboo 7.0.1. Related tickets on the public tracker include BSERV-20604, CONFSERVER-104488, JRASERVER-79546, JSDSERVER-16809, BAM-26567, CWD-6610, CRUC-8741, and FE-7583.
Affected Cloud products have already been patched, Atlassian said in the advisory and again on its Trust Center at 21:51 UTC on October 5, and its investigation found no evidence of exploitation there. Cloud customers do not need to act. Bitbucket Cloud is not in the affected set.
Server Editions Appear in the CVE With No Fixes
The product advisory talks about Data Center. The CVE record also marks every version of Bamboo Server, Bitbucket Server, Confluence Server, and Crowd Server as affected, and it lists no fixed releases for those four. Jira Software Server is listed as unaffected from 9.12.40, Jira Service Management Server from 5.12.40, and Crucible Server and Fisheye Server from 4.9.15. The record does not say whether a Server license can run those builds.
That gap is not a paperwork quirk. As of February 15, 2024 PT, Atlassian says Server products are no longer supported. Support and bug fixes stopped that day for Jira Software Server, Jira Core Server, Jira Service Management Server, Confluence Server, Bitbucket Server, Crowd Server, Bamboo Server, and their Server apps. Anyone still on those binaries has been off the vendor’s patch train for the entire life of this disclosure.
SERVER LINES WITH NO FIX IN THE CVE RECORD
- Bamboo Server: Every version listed as affected, with no patch version.
- Bitbucket Server: Every version listed as affected, with no patch version.
- Confluence Server: Every version listed as affected, with no patch version.
- Crowd Server: Every version listed as affected, with no patch version, and Crowd has had no Server release since 5.2 in September 2023.
Fisheye and Crucible still sit on a slower sunset. Customers can renew those licenses until May 15, 2028, and both received 4.9.15. Data Center itself still gets critical security fixes through March 28, 2029, when Atlassian plans to make those subscriptions expire. In a September 2025 post, the company said 99 percent of its 300,000-plus customers were already on Cloud. The 9.3 notice is for the remainder that still runs the software themselves, including boxes that never left Server.
Crowd 7.1.7 Versus the Record’s 7.1.1
Even Data Center admins who can patch have to pick a number out of a messy record. The advisory’s Crowd 7.1 fix is 7.1.7. The CVE record Atlassian filed lists 7.1.1 in its details and again as an unaffected patch version. Crowd 7.1.1 shipped on November 27, 2025, more than 10 months before this disclosure. On the Crowd ticket, the fix-version field says 7.1.7, while a table in the same ticket shows 7.1.6 and also lists 7.1.6 as affected.
Bamboo has the same kind of split. The advisory and the CVE description both say 10.2.24. One field on the CVE record says the 10.2 line is unaffected from 10.2.4.
WHERE ATLASSIAN’S OWN NUMBERS DIVERGE
| Product line | October 5 advisory | CVE record field |
|---|---|---|
| Crowd 7.1 | 7.1.7 | 7.1.1 |
| Bamboo 10.2 | 10.2.24 | 10.2.4 |
Install the advisory builds. Treat 7.1.1 and 10.2.4 as filing errors until Atlassian changes the advisory, because a Crowd 7.1.1 that has been in the wild since November 2025 cannot be the patch for a bug disclosed in October 2026 if later 7.1 builds are still listed as affected.
Default Jira Installs Give Up WEB-INF Files
watchTowr Labs spent October 6 reversing the advisory’s “arbitrary file access” wording and said it is an arbitrary file read. The researchers wrote that they could not climb outside the Tomcat context, and that they could read any file inside the application server itself, with the route varying by product. They shipped a detection script for Jira, Confluence, and Bitbucket the same day.
We're back, analyzing CVE-2026-21589 – an Arbitrary File Read vulnerability in Atlassian Jira, Confluence, BitBucket and more…
Enjoy!https://t.co/J077HITrVI
— watchTowr (@watchtowrcyber) October 6, 2026
Horizon3.ai’s attack engineer Zach Hanley reversed the issue independently. The firm’s October 6 note said default Jira deployments are likely exposed, that config files can hold credentials, and that a large number of instances look exploitable from the internet. A first pass said Confluence needed extra preconditions and that a default Confluence install was not exposed. Horizon3 later posted a correction: Confluence and Bitbucket are both exploitable in default installs.
Default Jira deployments are likely exposed
Horizon3.ai, Rapid Response advisory, on X, October 6, 2026
Some operators still argue the web root is empty of anything worth taking. That shrug collides with Horizon3’s follow-up on default Confluence and Bitbucket, and with Atlassian’s own note that some setups keep sensitive files in that folder. Public proof-of-concept code for the new CVE was circulating by October 6. A Nuclei template from ProjectDiscovery landed on October 7, which is the point at which internet-facing Jira, Confluence, and Bitbucket boxes should be assumed to be probed, whether or not anyone has published a confirmed break-in.
WAF Rules That Only Buy Time
Atlassian tells customers who cannot upgrade in one pass to take the instance offline if they can. Any instance reachable from the public internet, including one that already demands a login, should be cut off from outside networks until it is upgraded or a temporary block is in place. The CVE record labels the bug a path traversal. The company published three temporary rules, all of them aimed at requests whose URL contains.. directly next to /, \, or::, including URL-encoded forms.
THREE TEMPORARY BLOCKS ATLASSIAN PUBLISHED
- All eight products: A web application firewall or reverse-proxy rule that drops matching URLs.
- Confluence, Jira Software, Jira Service Management, Bamboo, and Crowd: A Tomcat RewriteValve rule on every node, which needs a shutdown and restart.
- Bitbucket: A urlrewrite.xml rule on every node, mirror, and mirror farm node, then a restart. Crucible and Fisheye get only the firewall option.
The product tickets say those blocks “are limited and not a replacement for patching your instance.” If the upgrade cannot happen at once, the next-best move Atlassian describes is still isolation, not a rewrite rule left in place as a long-term control.
Atlassian Cannot Confirm Self-Hosted Break-Ins
The cloud side of the house is the part Atlassian can see. It says those products are patched and that it has not found evidence of exploitation there. On customer-run instances it is blunt in the other direction.
Atlassian cannot confirm if your instances have been affected by this vulnerability
Atlassian, CVE-2026-21589 security advisory, October 5, 2026
It asks security teams to search access logs. One method is to URL-decode each request line, up to two times, and look for.. sitting directly next to /, \, or::. The other is to run Atlassian’s block pattern over the raw log lines. The advisory does not say how to tell a failed probe from a request that actually returned a file, and it does not say what a customer who finds those lines should do after the upgrade besides the upgrade itself.
WHAT WE KNOW
- Cloud: Affected Cloud products were patched before or with the October 5 notice, and Atlassian says it has not found exploitation there.
- Patches: Numbered Data Center, Crucible, and Fisheye builds exist; the working Crowd 7.1 target in the advisory is 7.1.7.
- Prior art: CVE-2021-26086 was the same class of Jira file read and is on CISA’s exploited catalog.
WHAT IS UNCONFIRMED
- On-prem attacks: Atlassian will not say whether self-hosted instances have been hit.
- Server upgrades: The CVE lists four Server products as affected with no fix, and does not say whether Server licenses can run the Data Center builds that close Jira and Jira Service Management.
- Which files: Atlassian has not identified the sensitive files or the setups that hold them, nor why subsequent systems scored high.
A Nuclei template for CVE-2026-21589 appeared on October 7. Data Center admins have numbered builds to install. Server boxes that never moved still do not.
-
NEWS1 month agoTozorakimab Opens a COPD Lane Other Biologics Shut
-
ENTERTAINMENT1 month agoAstro City Still Pays Off a 1995 Superhero Wager
-
NEWS1 month agoAcetaminophen Liver Injuries Soared After a Narrow FDA Cap
-
BUSINESS1 month agoCalvin Klein’s Record Jung Kook Collab Could Not Lift Sales
-
GAMING1 month agoSony’s 10 Percent Disc Cut Leaves New Games Digital
-
BUSINESS1 month agoTrump’s Embargo Threat Spends the Leverage It Needs
-
ENTERTAINMENT1 month agoLionel Richie Faces Heart Tests After the Muny Show
-
NEWS1 month agoTexas Puts a Human on Every Consequential AI Decision
