Cyber Security News

Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products

Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence, and Bitbucket. Tracked as CVE-2026-21589, the flaw has a CVSS score of 9.3. It lets unauthenticated attackers access specific files in an affected application’s web root directory.

The advisory, published on October 5, 2026, covers Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye.

Atlassian urges customers running affected installations to patch immediately. The vulnerability exposes files within the web application root directory without requiring an attacker to sign in.

However, exploitation requires knowing the target file’s exact name and path. Attackers cannot use this flaw to list directory contents or automatically discover available files.

This limitation narrows the attack, but does not remove the danger. Atlassian warns that some configurations may store sensitive files in accessible locations, increasing the impact of a successful exploit.

The disclosed behavior concerns file access it should not be interpreted as confirmed unrestricted access to every file on the underlying server.

Atlassian Patches Critical Vulnerabilities

Atlassian describes all unpatched versions of the listed products as affected. Older installations outside the vendor’s support window may also be vulnerable, so organizations maintaining legacy deployments should upgrade to supported, fixed releases.

For Jira Software Data Center, the fixed releases are 9.12.40, 10.3.26, and 11.3.12. Jira Service Management Data Center users should upgrade to 5.12.40, 10.3.26, or 11.3.12. Confluence Data Center fixes are available in 9.2.26 and 10.2.19.

Bitbucket Data Center customers should install 9.4.26, 10.2.8, or 10.5.1. Bamboo Data Center fixes are available in 10.2.24 and 12.1.12. The advisory lists Crowd Data Center fixes as 6.3.7, 7.0.3, 7.1.7, and 7.2.4. Crucible and Fisheye users should upgrade to 4.9.15.

Administrators should use Atlassian’s product advisory when selecting their upgrade target. Each affected installation needs attention; updating one product does not address vulnerable deployments of the others.

Atlassian recommends installing a listed fixed release or the latest version. Organizations unable to patch immediately should remove affected instances from the public internet where possible.

Atlassian says externally accessible installations require restrictions even when user authentication protects normal application access, because exploitation does not require authenticated access.

One temporary option is a web application firewall or reverse proxy rule using Atlassian-supplied regular expressions. The rule blocks traversal patterns involving adjacent dots and path separators, including encoded variants. Administrators must test that their implementation handles the specified patterns correctly.

Another option uses Tomcat’s RewriteValve with Atlassian-supplied rewrite configuration. Administrators should back up the instance, stop each cluster node, enable the valve, install the configuration, and restart the node. These measures are temporary and not a substitute for patching.

Atlassian says affected Cloud products have already been patched, with no customer action required. Its investigation found no evidence of exploitation.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…

4 minutes ago

FBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of Employees

The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…

5 minutes ago

Google Adds 6 Advanced Protection Features to Android 17 Against Sophisticated Attacks

Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and…

34 minutes ago

Top 10 Best SAST Tools in 2026 [Ranked & Scored]

The AI-code flood made one truth undeniable: static analysis only matters if developers fix what…

1 hour ago

Top 10 Best Just-in-Time (JIT) Access Tools in 2026 [Ranked & Scored]

Credentials that always work are credentials worth stealing which is why mitigating how attackers exploit…

2 hours ago

Hacker Group Claims to Have Stolen Trump Mobile Customers’ Personal Data

Trump Mobile customers’ personal data has appeared on a dark web leak site after a…

7 hours ago