News with an accent.

Blue Atlassian logo on a white background.
Privacy

Atlassian patches critical flaw in Jira, Confluence, Bitbucket

CVE-2026-21589 lets an unauthenticated attacker read certain files in eight self-hosted Data Center products, and a patch is available.

Atlassian published a security advisory for CVE-2026-21589 on Oct. 5, an arbitrary file access flaw rated critical at 9.3 out of 10 on the CVSS 4.0 scale. It affects every version before the fixed ones of eight products that organizations run on their own servers: the Data Center editions of Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd, plus Crucible and Fisheye.

According to the company, someone with no account at all can read certain files in the web application's root folder. The attacker first has to know the file's exact name and path, because the flaw cannot be used to list directories. Atlassian warns that some configurations leave sensitive files exposed, which raises the risk.

Atlassian Cloud customers have already received the fix and need to do nothing, the advisory says. The company says its investigation found no evidence of exploitation. BleepingComputer reported on Oct. 6 that there is no sign of attacks in the wild either.

Which versions fix the flaw

Atlassian recommends upgrading to one of these versions or a later one. The list was checked against the advisory's original table.

Fixed versions for CVE-2026-21589
ProductFixed versions
Bitbucket Data Center9.4.26, 10.2.8, 10.5.1
Confluence Data Center9.2.26, 10.2.19
Jira Service Management Data Center5.12.40, 10.3.26, 11.3.12
Jira Software Data Center9.12.40, 10.3.26, 11.3.12
Bamboo Data Center10.2.24, 12.1.12
Crowd Data Center6.3.7, 7.0.3, 7.1.7, 7.2.4
Crucible4.9.15
Fisheye4.9.15
Source: Atlassian

For those who cannot upgrade right away, the advisory describes three temporary mitigations: a rule in the web application firewall or proxy, enabling Tomcat's RewriteValve in the products that use it, and a URL rewrite rule in Bitbucket. The company also asks that the instance be taken off the internet in the meantime, if possible, even when it requires a login.

The score and the version list are the vendor's own, and there is no independent assessment of severity. Atlassian does not say who found the flaw, and this newsroom did not check the catalog of known exploited vulnerabilities kept by the U.S. agency CISA, where an entry could appear if the attack picture changes.

Keep reading

El Mediático uses cookies to measure its audience and, where advertising is active, to show ads. You can accept all, reject all, or choose what to allow. The cookie policy is available in Spanish only. More about cookies (Spanish)