Admins running Atlassian software in its Data Center editions need to act quickly. A vulnerability lets unauthenticated attackers access files in the web app. Atlassian urges customers to install the updates or at least apply mitigations.
According to the security advisory, attackers can reach certain files in the web app's root directory without logging in. They need to know the exact file name and path, as listing files isn't possible. In some configurations, which Atlassian doesn't specify, sensitive files may sit there, which raises the risk. The flaw is tracked as CVE-2026-21589, rated CVSS4 9.3, which makes it critical.
What that means in practice is explained by security researchers at watchTowr Labs in their analysis. Environments that run several Atlassian applications side by side, such as Jira, Confluence, and Bitbucket, often use Crowd, Atlassian's own single sign-on software. Each application needs credentials for Crowd, which are stored in a configuration file. The researchers showed that they could use CVE-2026-21589 to get at that file, read the password, and create an admin account in the targeted Jira. The elevated risk, then, is a privilege escalation.
Affected software and updates
All versions of the following products are vulnerable. The fixes are in Bitbucket Data Center (9.4.26, 10.2.8, 10.5.1), Confluence Data Center (9.2.26, 10.2.19), Jira Service Management Data Center (5.12.40, 10.3.26, 11.3.12), Jira Software Data Center (9.12.40, 10.3.26, 11.3.12), Bamboo Data Center (10.2.24, 12.1.12), Crowd Data Center (6.3.7, 7.0.3, 7.1.7, 7.2.4), Crucible (4.9.15), and Fisheye (4.9.15). Atlassian has already secured cloud instances, and says it has found no signs that the flaw has been abused.
Mitigations and hunting for traces
If you can't update right away, take publicly reachable instances off the internet if possible. Atlassian also recommends a web application firewall rule that filters requests by regex and blocks path manipulation with dot-dot sequences and their encoded variants. For Confluence, Jira, Jira Service Management, Bamboo, and Crowd, malicious requests can also be intercepted with Tomcat's RewriteValve, and for Bitbucket Atlassian provides a rule for the urlrewrite.xml configuration file.
Admins should also check their instances for signs of attack. In the access logs, Atlassian suggests URL-decoding every request and then looking for character sequences such as "/", "", or "::" in paths. In the undecoded log, the regex filter should match as well. Back in mid-September, Atlassian had already closed several vulnerabilities across its product line, and attackers could, among other things, snoop on Confluence Data Center.