Skip to content
Secure Contact

October 8, 2026

CVE-2026-21589: Patch Your Data Centre Instances

CVE

Critical Atlassian Flaw CVE-2026-21589: Patch Your Data Centre Instances Now

Published October 8, 2026

Atlassian has warned customers about CVE-2026-21589, a critical (CVSS 9.3) arbitrary file access vulnerability affecting its self-hosted Data Centre products. It can be exploited without authentication, and Atlassian is telling administrators to act now.

What is the vulnerability?

The flaw allows an unauthenticated attacker to access specific files within the web application root directory. Atlassian says exploitation requires prior knowledge of the target file’s exact name and path, and that the bug does not let attackers enumerate or list directory contents.

That requirement lowers the risk, but it doesn’t remove it. Atlassian also warns that in some configurations, sensitive files in the web root can increase your exposure. Application and configuration files often sit in well-known locations.

Who is affected?

All Data Center versions released before the fixed releases are affected. The list includes:

  • Confluence Data Centre
  • Jira Software and Jira Service Management Data Centre
  • Bitbucket Data Centre
  • Bamboo, Crowd, Crucible and Fisheye

End-of-life versions may also be vulnerable, so Atlassian recommends moving to a supported fixed version.

Using Atlassian Cloud? You don’t need to do anything. Atlassian has already patched its cloud products and reports no evidence of exploitation there.

Is it being exploited?

Atlassian says it has no evidence of exploitation at this time. But this is an unauthenticated, network-reachable bug in a widely deployed platform, and attackers often move fast once an advisory is public. Treat the lack of reported exploitation as a head start, not a reason to wait.

What you should do

  1. Upgrade to a fixed version listed in Atlassian’s advisory for your product.
  2. Restrict internet exposure. Atlassian advises that public-facing instances, even those with user authentication, should be blocked from external access until patched.
  3. Apply the temporary mitigation if you can’t patch immediately. Atlassian provides a rewrite.config file and instructions involving server.xml. Back up existing files first and follow the advisory exactly.
  4. Review your access logs for the traversal patterns described in Atlassian’s bulletin.
  5. Audit your web root for backups, keys or config files that shouldn’t be there.

Bottom line

If you run self-hosted Atlassian software, make this a priority today. Patch, lock down external access, and check your logs. Confirm version numbers and mitigation steps against Atlassian’s official CVE-2026-21589 advisory before changing production systems.

Sources: Atlassian security advisories, BleepingComputer, The Register, NVD/OpenCVE.

Leave a Reply

Your email address will not be published. Required fields are marked *


Math Captcha
26 − 18 =