Atlassian disclosed CVE-2026-21589, a critical (9.3 / CVSS 4.0) flaw letting unauthenticated attackers read specific files from the web-application root of its Data Centre products — Jira Software, Confluence, Bitbucket, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. Exploiting it requires knowing a file's exact name and path, so it cannot list directory contents, but Atlassian notes its products install to well-documented default locations and that some configurations leave sensitive files exposed. Fixed releases were listed per product on 6 October; the cloud line is already patched with no evidence of cloud exploitation. For unpatched internet-facing instances Atlassian's first recommendation is to take them offline, and it provided WAF, Tomcat RewriteValve and Bitbucket urlrewrite.xml mitigation rules plus access-log search guidance. It also flagged CVE-2021-26086, a prior Jira path traversal, as precedent for attackers exploiting this class in the wild.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-07 |
| Source | iTnews |
| Reliability | Tier 3 |
| CVEs | CVE-2021-26086, CVE-2026-21589 |