ATLASSIAN has released patches for a critical self-managed vulnerability, CVE-2026-21589, classified as a path traversal flaw with a CVSS v4 score of 9.3. The bug allows an unauthenticated attacker to read files from the web application root by crafting a URL that traverses directories. In practice, exploitation does not require a login or user interaction, but attackers must know the exact name and path of the targeted file and cannot list directory contents.
Atlassian notes that in some configurations, there may be sensitive files that increase risk, but there is no indication of broad remote code execution or file deletion; the impact is arbitrary file access rather than execution.
The vulnerability affects eight Atlassian Data Center products: Jira Data Center and Jira Service Management Data Center, Confluence Data Center, Bitbucket Data Center, Bamboo Data Center, Crowd Data Center, and Fisheye/Crucible. Atlassian reports that cloud deployments have been patched and that there is no evidence of exploitation in cloud environments, while for self-managed instances, no in-the-wild exploitation has been confirmed at the time of the advisories.
Affected versions are all prior to the fixed releases. Fixes are delivered in multiple patch versions: Jira Data Center 9.12.40, 10.3.26 or 11.3.12; Jira Service Management Data Center 5.12.40, 10.3.26 or 11.3.12; Confluence Data Center 9.2.26 or 10.2.19; Bitbucket Data Center 9.4.26, 10.2.8 or 10.5.1; Bamboo Data Center 10.2.24 or 12.1.12; Crowd Data Center 6.3.7, 7.0.3, 7.1.7 or 7.2.4; Fisheye and Crucible 4.9.15.
Administrators are urged to upgrade to the indicated fixed versions or later as a matter of priority and, where patching cannot be applied immediately, to implement temporary mitigations such as internet exposure controls or web application firewall rules to block path traversal sequences.