www.rapid7.com 7 Oct 2026, 12:11 UTC

Atlassian Flaw Lets Unauthenticated Attackers Read Web Root Files

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

CVE- 2026-21589 is a critical unauthenticated arbitrary file access vulnerability disclosed by Atlassian on 5 October 2026, affecting eight Atlassian Data Centre products: Bitbucket Data Centre, Confluence Data Centre, Jira Service Management Data Centre, Jira Software Data Centre, Bamboo Data Centre, Crowd Data Centre, Crucible, and Fisheye.

An unauthenticated remote attacker who knows the exact name and path of a target file can read it from within the application’s web root, without the need for directory listing or enumeration. Atlassian assigns a CVSSv4 score of 9.3. Cloud deployments have been patched and require no action from customers; the issue affects on‑premises installations, including unsupported versions, until patched.

Rapid7’s coverage references a technical analysis showing a path traversal flaw in Atlassian’s web-resource handling, where double-colon sequences can be misinterpreted as path separators, enabling access to the resource-loading code and exfiltration of arbitrary files from the web root. Demonstrations indicated the ability to read files across the application, with credentials exposed in a WEB-INF/classes/crowd[.]properties file in an Jira‑configured Crowd deployment.

Atlassian’s guidance recommends upgrading to the fixed releases: Bitbucket Data Centre 9.4.26, 10.2.8, 10.5.1; Confluence Data Centre 9.2.26, 10.2.19; Jira Service Management Data Centre 5.12.40, 10.3.26, 11.3.12; Jira Software Data Centre 9.12.40, 10.3.26, 11.3.12; Bamboo Data Centre 10.2.24, 12.1.12; Crowd Data Centre 6.3.7, 7.0.3, 7.1.7, 7.2.4; Crucible 4.9.15; Fisheye 4.9.15.

Organisations should isolate affected systems from the internet or restrict external access if patching cannot be completed immediately, monitor access logs for exploitation attempts, and follow Atlassian’s guidance on URL-decoding and log analysis.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline