www.securityweek.com 7 Oct 2026, 06:37 UTC

Atlassian Patches Critical File Access Flaw Across Eight Products

Atlassian Patches Critical File Access Flaw Across Eight Products
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

ATLASSIAN has released patches for a critical vulnerability affecting eight of its products, tracked as CVE-2026-21589 with a CVSS score of 9.3. The flaw is described as an arbitrary file access issue that can be exploited without authentication to access specific files in the web application root directory. Exploitation requires knowledge of the exact target file’s name and path; the vulnerability does not allow attackers to enumerate directory contents. Atlassian notes that in some configurations there may be sensitive files present that raise the risk.

All versions of Bitbucket Data Center, Bamboo Data Center, Crowd Data Center, Crucible, Confluence Data Center, Fisheye, Jira Service Management Data Center, and Jira Software Data Center are affected. Patches have been issued in Bitbucket: 9.4.26, 10.2.8, and 10.5.1; Bamboo: 10.2.24 and 12.1.12; Confluence: 9.2.26 and 10.2.19; Crowd: 6.3.7, 7.0.3, 7.1.7, and 7.2.4; Crucible: 4.9.15; Fisheye: 4.9.15; Jira Service Management: 5.12.40, 10.3.26, and 11.3.12; Jira: 9.12.40, 10.3.26, and 11.3.12.

Organisations are urged to patch self-hosted deployments promptly or disconnect from the internet until fixes are applied; temporary mitigations are described in Atlassian’s advisory. While there is no evidence of active exploitation to date, security researchers warn that similar vulnerabilities have been used by ransomware groups and APTs, and eight Atlassian flaws sit on CISA’s KEV list.

WatchTowr cautions that, if Crowd is used for SSO, authentication details can be exposed in plaintext at a known path, enabling potential admin account creation if Crowd endpoints are reachable externally.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline