Full Report
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and
Analysis Summary
# Vulnerability: Atlassian Data Center Path Traversal (Arbitrary File Access)
## CVE Details
- **CVE ID:** CVE-2026-21589
- **CVSS Score:** 9.3 (Critical)
- **CWE:** Path Traversal (implied by mitigation and record details)
## Affected Systems
- **Products:**
- Bitbucket Data Center / Server
- Confluence Data Center / Server
- Jira Software Data Center / Server
- Jira Service Management Data Center / Server
- Bamboo Data Center / Server
- Crowd Data Center / Server
- Crucible / Crucible Server
- Fisheye / Fisheye Server
- **Versions:** All versions prior to the fixed releases listed below. Note: End-of-Life (EOL) versions are also likely affected.
- **Configurations:** Self-hosted (Data Center and Server) instances. Cloud products have already been patched by Atlassian.
## Vulnerability Description
A critical path traversal flaw exists in the web application root directory of multiple Atlassian products. An unauthenticated attacker can read specific files within the web application root directory by sending specially crafted requests. While the attacker cannot list directory contents, they can access sensitive configuration or system files if the exact filename and path are known.
## Exploitation
- **Status:** PoC availability and "in the wild" status not explicitly confirmed in text, but rated as Critical/9.3, indicating high exploitability.
- **Complexity:** Low (requires knowledge of file names/paths but no authentication).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Unauthorized access to sensitive web root files).
- **Integrity:** None reported.
- **Availability:** None reported.
## Remediation
### Patches
Atlassian recommends upgrading to the following versions (or later LTS releases):
- **Bitbucket:** 9.4.26, 10.2.8, 10.5.1
- **Confluence:** 9.2.26, 10.2.19
- **Jira Software:** 9.12.40, 10.3.26, 11.3.12
- **Jira Service Management:** 5.12.40, 10.3.26, 11.3.12
- **Bamboo:** 10.2.24, 12.1.12
- **Crowd:** 6.3.7, 7.0.3, 7.1.7, 7.2.4
- **Crucible / Fisheye:** 4.9.15
### Workarounds
If immediate patching is not possible:
1. **Network Restriction:** Take instances offline or restrict access to trusted internal networks only.
2. **WAF/Reverse Proxy:** Block requests where the URL contains `..` adjacent to `/`, `\`, or `::` (including URL-encoded variants).
3. **Tomcat Rewrite (Confluence, Jira, Bamboo, Crowd):** Implement a `RewriteValve` rule to block traversal sequences (requires restart).
4. **urlrewrite.xml (Bitbucket):** Apply specific blocking rules to all nodes and mirrors (requires restart).
## Detection
- **Indicators of Compromise:** Look for unusual GET requests in web server access logs containing path traversal sequences (`../`, `..%2f`, `..\\`) targeting the web root.
- **Detection Methods:** Monitor for unauthorized access to sensitive files like `web.xml` or configuration files within the application root.
## References
- Atlassian Advisory: hxxps://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html
- Bitbucket Ticket: hxxps://jira.atlassian.com/browse/BSERV-20604
- Confluence Ticket: hxxps://jira.atlassian.com/browse/CONFSERVER-104488
- CVE Record: hxxps://github.com/CVEProject/cvelistV5/blob/main/cves/2026/21xxx/CVE-2026-21589.json