Atlassian Data Center flaw CVE-2026-21589 needs urgent fix

Atlassian Data Center flaw CVE-2026-21589 needs urgent fix

Atlassian has told administrators of its self-hosted Data Center products to patch a critical vulnerability right away. The flaw, tracked as CVE-2026-21589, lets an attacker who has not logged in read certain files from an affected installation.

The company published its advisory on 5 October 2026. It rated the bug 9.3 on the CVSS 4.0 scale, based on its own internal assessment.

Almost the whole Data Center lineup is affected

CVE-2026-21589 is an arbitrary file access vulnerability. It affects all versions of these products:

  • Bitbucket Data Center
  • Confluence Data Center
  • Jira Software Data Center
  • Jira Service Management Data Center
  • Bamboo Data Center
  • Crowd Data Center
  • Crucible and Fisheye

Data Center is the edition of Atlassian's software that organizations install and run on their own servers. Atlassian manages the cloud version itself.

According to the advisory, an unauthenticated attacker can use the flaw to access "specific files within the web application root directory" on vulnerable versions. The company also warned that "in some configurations, there may be sensitive files present that increase your risk."

Limits on exploitation

The bug has some limits. An attacker must know the exact name and path of the file they want. The flaw cannot be used to list directories or enumerate their contents, so an attacker cannot simply browse a server.

Atlassian said its affected cloud products have already been patched. Its investigation found no evidence of exploitation there, and cloud customers do not need to do anything.

The advisory does not say whether attackers have exploited the flaw against Data Center instances. It also does not name who discovered it.

Fixed versions

Atlassian wants administrators to upgrade every affected installation to a fixed version or to the latest release. The patched builds are:

  • Bitbucket Data Center: 9.4.26, 10.2.8 and 10.5.1
  • Confluence Data Center: 9.2.26 and 10.2.19
  • Jira Software Data Center and Jira Service Management Data Center: 10.3.26 and 11.3.12, plus 9.12.40 for Jira Software and 5.12.40 for Jira Service Management
  • Bamboo Data Center: 10.2.24 and 12.1.12
  • Crowd Data Center: 6.3.7, 7.0.3, 7.1.7 and 7.2.4
  • Crucible and Fisheye: 4.9.15

Take exposed instances offline

If upgrading cannot happen right away, Atlassian suggests taking affected instances off the internet where possible.

"Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action," the company said.

Atlassian has also published three temporary mitigations for organizations that need more time to roll out the fixes.

The company said it cannot confirm whether any customer's instance has been affected. It advises security teams to check all affected instances for signs of compromise.

Why It Matters

Atlassian's tools often hold source code, internal documentation, tickets and, in the case of Crowd, identity data. That makes even a limited file-read bug worth taking seriously. The need to know exact file paths raises the bar somewhat, but default file locations in widely deployed software are rarely secret. This suggests the requirement may slow attackers less than it first appears.

The advisory also fits a familiar pattern. Self-hosted enterprise software keeps drawing critical fixes, as seen recently with an out-of-band Exchange Server patch and a NetScaler zero-day. Vendors fix their cloud services directly, but on-premise customers must patch for themselves.

It is worth watching whether exploitation reports for Data Center instances appear in the coming days. Researchers may also publish details on which "sensitive files" raise the risk.