Connect with us

NEWS

Atlassian’s 9.3 File-Read Bug Repeats a 2021 Exploited Flaw

CVE-2026-21589 scores 9.3 across eight Atlassian Data Center products, echoing a 2021 Jira file-read later listed as exploited.

Published

on

Atlassian scored CVE-2026-21589 a 9.3 on October 5, 2026, across eight self-hosted Data Center products. An attacker with no login can read a file in the web application root if they already know its exact path.

The last time Jira exposed files this way, the U.S. Cybersecurity and Infrastructure Security Agency later put that older bug on its exploited list. This one is wider, and the leftover Server fleet has no vendor build to install.

A 2021 Jira File Read Later Made CISA’s Exploited List

On August 16, 2021, Atlassian published CVE-2021-26086. The National Vulnerability Database still describes it as a path traversal in the /WEB-INF/web.xml endpoint on Jira Server and Data Center, scored 5.3, which let a remote attacker read particular files. Public proof-of-concept code was in Exploit-DB by October 6, 2021, 51 days later.

CISA added that Jira bug to its catalog of known exploited vulnerabilities on November 12, 2024, more than three years after disclosure, and gave federal agencies until December 3, 2024, to apply vendor mitigations or stop using the product. The “must already know the file name” limit did not keep it off that list.

THE LAST TIME FILES CAME OUT OF JIRA

  1. August 16, 2021: Atlassian publishes CVE-2021-26086, a path traversal that reads particular files through /WEB-INF/web.xml on Jira Server and Data Center.
  2. October 6, 2021: A public exploit for Jira Server and Data Center 8.16.0 is listed in Exploit-DB.
  3. November 12, 2024: CISA adds the bug to its exploited catalog and sets a December 3, 2024 deadline.
  4. October 5, 2026: Atlassian publishes CVE-2026-21589, an unauthenticated file read across eight self-hosted products, scored 9.3.

The new bug is the same class of request: a path that climbs into the web application root, which is the folder that holds the app itself. Atlassian says the attacker cannot list that folder, and must already know the exact name and path. In some setups, it says, sensitive files sit there and raise the risk. It does not name those files, and it does not explain the high marks it gave for harm to other systems.

Which Atlassian Products Does CVE-2026-21589 Affect?

The October 5 advisory names Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. All versions before the listed fixes are in scope, including releases that have already reached end of life. Atlassian tells customers to move to a fixed long-term support release or later, and it published fixed versions for each product rather than a binary hot patch.

The company rates the flaw Critical at 9.3 under CVSS 4.0, with the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H. That scoring says the bug is reachable over the network with no login and no user click, that confidentiality on the vulnerable host is high, that integrity and availability on that host are none, and that confidentiality, integrity, and availability on subsequent systems are all high. Atlassian tells customers to judge how that applies to their own setup.

FIXED VERSIONS IN THE OCTOBER 5 ADVISORY

Product Fixed versions
Bitbucket Data Center 9.4.26, 10.2.8, 10.5.1
Confluence Data Center 9.2.26, 10.2.19
Jira Software Data Center 9.12.40, 10.3.26, 11.3.12
Jira Service Management Data Center 5.12.40, 10.3.26, 11.3.12
Bamboo Data Center 10.2.24, 12.1.12
Crowd Data Center 6.3.7, 7.0.3, 7.1.7, 7.2.4
Crucible 4.9.15
Fisheye 4.9.15

The CVE record Atlassian filed goes further back than those patch lines. It says the flaw was introduced in Confluence 5.10.0, in Bitbucket 4.6.0, in Jira Software 7.1.0, in Jira Service Management 3.1.0, in Crowd 2.11.0, and in Bamboo 7.0.1. Related tickets on the public tracker include BSERV-20604, CONFSERVER-104488, JRASERVER-79546, JSDSERVER-16809, BAM-26567, CWD-6610, CRUC-8741, and FE-7583.

Affected Cloud products have already been patched, Atlassian said in the advisory and again on its Trust Center at 21:51 UTC on October 5, and its investigation found no evidence of exploitation there. Cloud customers do not need to act. Bitbucket Cloud is not in the affected set.

Server Editions Appear in the CVE With No Fixes

The product advisory talks about Data Center. The CVE record also marks every version of Bamboo Server, Bitbucket Server, Confluence Server, and Crowd Server as affected, and it lists no fixed releases for those four. Jira Software Server is listed as unaffected from 9.12.40, Jira Service Management Server from 5.12.40, and Crucible Server and Fisheye Server from 4.9.15. The record does not say whether a Server license can run those builds.

That gap is not a paperwork quirk. As of February 15, 2024 PT, Atlassian says Server products are no longer supported. Support and bug fixes stopped that day for Jira Software Server, Jira Core Server, Jira Service Management Server, Confluence Server, Bitbucket Server, Crowd Server, Bamboo Server, and their Server apps. Anyone still on those binaries has been off the vendor’s patch train for the entire life of this disclosure.

SERVER LINES WITH NO FIX IN THE CVE RECORD

  • Bamboo Server: Every version listed as affected, with no patch version.
  • Bitbucket Server: Every version listed as affected, with no patch version.
  • Confluence Server: Every version listed as affected, with no patch version.
  • Crowd Server: Every version listed as affected, with no patch version, and Crowd has had no Server release since 5.2 in September 2023.

Fisheye and Crucible still sit on a slower sunset. Customers can renew those licenses until May 15, 2028, and both received 4.9.15. Data Center itself still gets critical security fixes through March 28, 2029, when Atlassian plans to make those subscriptions expire. In a September 2025 post, the company said 99 percent of its 300,000-plus customers were already on Cloud. The 9.3 notice is for the remainder that still runs the software themselves, including boxes that never left Server.

Crowd 7.1.7 Versus the Record’s 7.1.1

Even Data Center admins who can patch have to pick a number out of a messy record. The advisory’s Crowd 7.1 fix is 7.1.7. The CVE record Atlassian filed lists 7.1.1 in its details and again as an unaffected patch version. Crowd 7.1.1 shipped on November 27, 2025, more than 10 months before this disclosure. On the Crowd ticket, the fix-version field says 7.1.7, while a table in the same ticket shows 7.1.6 and also lists 7.1.6 as affected.

Bamboo has the same kind of split. The advisory and the CVE description both say 10.2.24. One field on the CVE record says the 10.2 line is unaffected from 10.2.4.

WHERE ATLASSIAN’S OWN NUMBERS DIVERGE

Product line October 5 advisory CVE record field
Crowd 7.1 7.1.7 7.1.1
Bamboo 10.2 10.2.24 10.2.4

Install the advisory builds. Treat 7.1.1 and 10.2.4 as filing errors until Atlassian changes the advisory, because a Crowd 7.1.1 that has been in the wild since November 2025 cannot be the patch for a bug disclosed in October 2026 if later 7.1 builds are still listed as affected.

Default Jira Installs Give Up WEB-INF Files

watchTowr Labs spent October 6 reversing the advisory’s “arbitrary file access” wording and said it is an arbitrary file read. The researchers wrote that they could not climb outside the Tomcat context, and that they could read any file inside the application server itself, with the route varying by product. They shipped a detection script for Jira, Confluence, and Bitbucket the same day.

Horizon3.ai’s attack engineer Zach Hanley reversed the issue independently. The firm’s October 6 note said default Jira deployments are likely exposed, that config files can hold credentials, and that a large number of instances look exploitable from the internet. A first pass said Confluence needed extra preconditions and that a default Confluence install was not exposed. Horizon3 later posted a correction: Confluence and Bitbucket are both exploitable in default installs.

Default Jira deployments are likely exposed

Horizon3.ai, Rapid Response advisory, on X, October 6, 2026

Some operators still argue the web root is empty of anything worth taking. That shrug collides with Horizon3’s follow-up on default Confluence and Bitbucket, and with Atlassian’s own note that some setups keep sensitive files in that folder. Public proof-of-concept code for the new CVE was circulating by October 6. A Nuclei template from ProjectDiscovery landed on October 7, which is the point at which internet-facing Jira, Confluence, and Bitbucket boxes should be assumed to be probed, whether or not anyone has published a confirmed break-in.

WAF Rules That Only Buy Time

Atlassian tells customers who cannot upgrade in one pass to take the instance offline if they can. Any instance reachable from the public internet, including one that already demands a login, should be cut off from outside networks until it is upgraded or a temporary block is in place. The CVE record labels the bug a path traversal. The company published three temporary rules, all of them aimed at requests whose URL contains.. directly next to /, \, or::, including URL-encoded forms.

THREE TEMPORARY BLOCKS ATLASSIAN PUBLISHED

  • All eight products: A web application firewall or reverse-proxy rule that drops matching URLs.
  • Confluence, Jira Software, Jira Service Management, Bamboo, and Crowd: A Tomcat RewriteValve rule on every node, which needs a shutdown and restart.
  • Bitbucket: A urlrewrite.xml rule on every node, mirror, and mirror farm node, then a restart. Crucible and Fisheye get only the firewall option.

The product tickets say those blocks “are limited and not a replacement for patching your instance.” If the upgrade cannot happen at once, the next-best move Atlassian describes is still isolation, not a rewrite rule left in place as a long-term control.

Atlassian Cannot Confirm Self-Hosted Break-Ins

The cloud side of the house is the part Atlassian can see. It says those products are patched and that it has not found evidence of exploitation there. On customer-run instances it is blunt in the other direction.

Atlassian cannot confirm if your instances have been affected by this vulnerability

Atlassian, CVE-2026-21589 security advisory, October 5, 2026

It asks security teams to search access logs. One method is to URL-decode each request line, up to two times, and look for.. sitting directly next to /, \, or::. The other is to run Atlassian’s block pattern over the raw log lines. The advisory does not say how to tell a failed probe from a request that actually returned a file, and it does not say what a customer who finds those lines should do after the upgrade besides the upgrade itself.

WHAT WE KNOW

  • Cloud: Affected Cloud products were patched before or with the October 5 notice, and Atlassian says it has not found exploitation there.
  • Patches: Numbered Data Center, Crucible, and Fisheye builds exist; the working Crowd 7.1 target in the advisory is 7.1.7.
  • Prior art: CVE-2021-26086 was the same class of Jira file read and is on CISA’s exploited catalog.

WHAT IS UNCONFIRMED

  • On-prem attacks: Atlassian will not say whether self-hosted instances have been hit.
  • Server upgrades: The CVE lists four Server products as affected with no fix, and does not say whether Server licenses can run the Data Center builds that close Jira and Jira Service Management.
  • Which files: Atlassian has not identified the sensitive files or the setups that hold them, nor why subsequent systems scored high.

A Nuclei template for CVE-2026-21589 appeared on October 7. Data Center admins have numbered builds to install. Server boxes that never moved still do not.

Harry is the editor of BLUE HOLE MEN, his own independent publication and the product of ten years in journalism that moved him from reporting to editing. Attribution is where he is most exacting. A quotation is reproduced from the transcript or recording, a paraphrase is labelled as one, and a claim from a press release is described as a company's claim rather than as fact. Unnamed sources are used rarely, and when they are, the article explains why the name is withheld and what the person is in a position to know. Statistics are attributed to the dataset or filing they came from, and every one is checked before publication. That standard governs the whole site, which covers news, business, technology and science together with sports, entertainment, lifestyle, travel, auto and gaming, for readers across many countries. Reviews in the technology, auto and gaming pages rest on products Harry has used himself. Errors are corrected under a public corrections policy, with the correction visible on the article. Reader mail reaches him at support@blueholemen.com.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending