Open Nav
Sign Up

Atlassian CVE-2026-21589: Critical Pre-Auth File Read Affects Jira, Confluence, Bitbucket and More

atlassian_cve-2026-21589

Filip Dimitrov

October 7, 2026

Atlassian has issued an urgent security advisory for CVE-2026-21589, a critical vulnerability affecting eight of its self-hosted Data Center products, including Jira, Confluence and Bitbucket.

The vulnerability allows a remote attacker who has not authenticated to retrieve specific files from an affected application’s web root. Atlassian has assigned the flaw a CVSS 4.0 score of 9.3, with no privileges, user interaction or special attack conditions required.

Atlassian says exploitation requires an attacker to know the exact name and path of the target file and does not provide the ability to list directories. That limitation reduces opportunistic data discovery, but it does not remove the risk. Configuration files and other predictable resources may exist at known locations, and security researchers have already demonstrated how the flaw can expose highly sensitive credentials in certain deployments.

How CVE-2026-21589 works

Researchers traced the vulnerability to Atlassian’s shared web-resource functionality. Their analysis identified differences in versions of the atlassian-plugins-webresource component and examined how application resource paths are processed.

One important behaviour is Atlassian’s use of double colons (::) as an encoded representation of forward slashes. Under vulnerable conditions, manipulated resource paths can abuse this processing to traverse directories inside the web application’s context and reach files that should not be directly accessible over HTTP.

Researchers successfully reproduced the issue against Jira, Confluence and Bitbucket. Although the traversal does not appear to provide unrestricted access to the entire underlying operating system, it can expose files within the application’s web root and associated WEB-INF directories.

That distinction matters because Atlassian applications can keep configuration material inside those directories.

When file disclosure becomes credential compromise

The most concerning scenario identified so far involves environments integrated with Atlassian Crowd, the company’s identity and single sign-on platform.

Atlassian’s documented Crowd integration can place a crowd.properties configuration file under WEB-INF/classes/. This file can contain an application’s Crowd username, Crowd server address and application password in plaintext.

If an attacker knows that predictable path and successfully retrieves the configuration file, the impact may extend far beyond information disclosure.

The exposed Crowd application credentials could subsequently be used to interact with Crowd’s user-management functionality. Where Crowd is reachable and the compromised application account has sufficient rights, researchers demonstrated the ability to create users and assign administrative privileges.

This attack chain is configuration-dependent and should not be interpreted as universal remote administrator access across every vulnerable Atlassian deployment. Crowd access controls, network segmentation and application permissions can significantly affect the result.

Affected and fixed versions

Atlassian states that all affected product versions prior to the following fixed releases should be considered vulnerable. Administrators should move to a fixed release for their branch or preferably the latest supported version.

ProductFixed versions
Bitbucket Data Center9.4.26, 10.2.8, 10.5.1
Confluence Data Center9.2.26, 10.2.19
Jira Service Management Data Center5.12.40, 10.3.26, 11.3.12
Jira Software Data Center9.12.40, 10.3.26, 11.3.12
Bamboo Data Center10.2.24, 12.1.12
Crowd Data Center6.3.7, 7.0.3, 7.1.7, 7.2.4
Crucible4.9.15
Fisheye4.9.15

Atlassian Cloud customers do not need to take action. Atlassian says affected cloud services have already been patched.

Recommended actions

  1. Patch immediately. Upgrade all affected Atlassian Data Center products to one of the vendor’s fixed releases or the newest supported version.
  2. Prioritise internet-facing systems. Jira, Confluence, Bitbucket or other affected services exposed directly to the internet should be treated as the highest priority.
  3. Restrict external access if patching cannot be completed immediately. Atlassian specifically recommends removing vulnerable instances from the public internet where possible.
  4. Deploy Atlassian’s temporary WAF or URL-rewrite mitigations. The vendor provides filtering guidance for all affected products, Tomcat RewriteValve mitigations for Jira, JSM, Confluence, Bamboo and Crowd, and a separate URL rewrite mitigation for Bitbucket. Apply changes across every cluster node, including Bitbucket mirrors where applicable.
  5. Review historical access logs. Search both raw and decoded URLs for traversal patterns described in Atlassian’s advisory.
  6. Investigate potential credential exposure. In environments using Crowd or other sensitive configuration files inside the web application context, determine whether those files could have been accessed. If evidence suggests successful retrieval, rotate exposed credentials and investigate downstream identity activity.


Stay Safe. Stay Secure.

OP Innovate Research Team

Under Cyber Attack?

Fill out the form and we will contact you immediately.