thehackernews.com 6 Oct 2026, 06:58 UTC

Atlassian warns of critical flaw exposing files in self-hosted products

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

ATLASSIAN has disclosed a critical path-traversal flaw affecting eight self-hosted Data Centre products that could allow unauthenticated attackers to read specific files in the web application root directory. Exploitation does not require login or directory listing; the attacker must know the exact file name and path. The vulnerability is tracked as CVE-2026-21589 and Atlassian assigns a CVSS v4 score of 9.3. They note cloud products are already patched and do not require action by customers.

Affected products and fixed versions are detailed by Atlassian as of 6 October 2026. Bitbucket Data Centre users should upgrade to 9.4.26, 10.2.8, or 10.5.1; Confluence Data Centre to 9.2.26 or 10.2.19; Jira Software Data Centre to 9.12.40, 10.3.26, or 11.3.12; Jira Service Management Data Centre to 5.12.40, 10.3.26, or 11.3.12; Bamboo Data Centre to 10.2.24 or 12.1.12; Crowd Data Centre to 6.3.7, 7.0.3, 7.1.7, or 7.2.4; and Crucible and Fisheye to 4.9.15.

The advisory also notes discrepancies in the CVE record for some products and versions, and that with some server editions no fixed versions are listed. If upgrading all at once is not possible, Atlassian recommends taking affected instances offline or restricting internet exposure and applying mitigations, though these are described as limited and not a replacement for patching.

The advisory also urges security teams to search logs for suspicious requests, while cautioning that it is not clear whether on-prem exploits have been observed.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline