Atlassian has issued an urgent security advisory for CVE-2026-21589, a critical vulnerability affecting eight of its self-hosted Data Center products, including Jira, Confluence and Bitbucket.
The vulnerability allows a remote attacker who has not authenticated to retrieve specific files from an affected application’s web root. Atlassian has assigned the flaw a CVSS 4.0 score of 9.3, with no privileges, user interaction or special attack conditions required.
Atlassian says exploitation requires an attacker to know the exact name and path of the target file and does not provide the ability to list directories. That limitation reduces opportunistic data discovery, but it does not remove the risk. Configuration files and other predictable resources may exist at known locations, and security researchers have already demonstrated how the flaw can expose highly sensitive credentials in certain deployments.
How CVE-2026-21589 works
Researchers traced the vulnerability to Atlassian’s shared web-resource functionality. Their analysis identified differences in versions of the atlassian-plugins-webresource component and examined how application resource paths are processed.
One important behaviour is Atlassian’s use of double colons (::) as an encoded representation of forward slashes. Under vulnerable conditions, manipulated resource paths can abuse this processing to traverse directories inside the web application’s context and reach files that should not be directly accessible over HTTP.
Researchers successfully reproduced the issue against Jira, Confluence and Bitbucket. Although the traversal does not appear to provide unrestricted access to the entire underlying operating system, it can expose files within the application’s web root and associated WEB-INF directories.
That distinction matters because Atlassian applications can keep configuration material inside those directories.
When file disclosure becomes credential compromise
The most concerning scenario identified so far involves environments integrated with Atlassian Crowd, the company’s identity and single sign-on platform.
Atlassian’s documented Crowd integration can place a crowd.properties configuration file under WEB-INF/classes/. This file can contain an application’s Crowd username, Crowd server address and application password in plaintext.
If an attacker knows that predictable path and successfully retrieves the configuration file, the impact may extend far beyond information disclosure.
The exposed Crowd application credentials could subsequently be used to interact with Crowd’s user-management functionality. Where Crowd is reachable and the compromised application account has sufficient rights, researchers demonstrated the ability to create users and assign administrative privileges.
This attack chain is configuration-dependent and should not be interpreted as universal remote administrator access across every vulnerable Atlassian deployment. Crowd access controls, network segmentation and application permissions can significantly affect the result.
Affected and fixed versions
Atlassian states that all affected product versions prior to the following fixed releases should be considered vulnerable. Administrators should move to a fixed release for their branch or preferably the latest supported version.
| Product | Fixed versions |
| Bitbucket Data Center | 9.4.26, 10.2.8, 10.5.1 |
| Confluence Data Center | 9.2.26, 10.2.19 |
| Jira Service Management Data Center | 5.12.40, 10.3.26, 11.3.12 |
| Jira Software Data Center | 9.12.40, 10.3.26, 11.3.12 |
| Bamboo Data Center | 10.2.24, 12.1.12 |
| Crowd Data Center | 6.3.7, 7.0.3, 7.1.7, 7.2.4 |
| Crucible | 4.9.15 |
| Fisheye | 4.9.15 |
Atlassian Cloud customers do not need to take action. Atlassian says affected cloud services have already been patched.
Recommended actions
- Patch immediately. Upgrade all affected Atlassian Data Center products to one of the vendor’s fixed releases or the newest supported version.
- Prioritise internet-facing systems. Jira, Confluence, Bitbucket or other affected services exposed directly to the internet should be treated as the highest priority.
- Restrict external access if patching cannot be completed immediately. Atlassian specifically recommends removing vulnerable instances from the public internet where possible.
- Deploy Atlassian’s temporary WAF or URL-rewrite mitigations. The vendor provides filtering guidance for all affected products, Tomcat RewriteValve mitigations for Jira, JSM, Confluence, Bamboo and Crowd, and a separate URL rewrite mitigation for Bitbucket. Apply changes across every cluster node, including Bitbucket mirrors where applicable.
- Review historical access logs. Search both raw and decoded URLs for traversal patterns described in Atlassian’s advisory.
- Investigate potential credential exposure. In environments using Crowd or other sensitive configuration files inside the web application context, determine whether those files could have been accessed. If evidence suggests successful retrieval, rotate exposed credentials and investigate downstream identity activity.
Stay Safe. Stay Secure.
OP Innovate Research Team



