Skip to the main content

Australia

Australia’s daily news

Tech

Atlassian fixes critical vulnerability across eight self-hosted products

The flaw can expose files to attackers who have not logged in. Atlassian says its affected Cloud services are patched and customers there need not act.

By Quang Dinh

Published 1 min read

Server racks in a data centre
Photo: iTnews

Eight self-hosted Atlassian products have received security fixes for CVE-2026-21589, which enables file access without a login. Atlassian gave the vulnerability an internal CVSS 4.0 rating of 9.3 out of 10.0 and said all versions earlier than the fixed releases were affected.

The affected products are Bamboo, Crowd Data Center, Bitbucket, Jira Service Management, Confluence, Jira Software, Crucible and Fisheye. The vulnerability permits access to files in an application's web root, but attackers must know the precise filename and path. It does not provide a directory listing.

Atlassian warned that certain configurations could expose sensitive files. For Cloud customers, the company said no action was necessary: it had applied patches to affected products and detected no evidence that the flaw had been exploited there.

Patched versions include Bitbucket 9.4.26, 10.2.8 and 10.5.1; Confluence 9.2.26 and 10.2.19; and Jira Software 9.12.40, 10.3.26 and 11.3.12.

Where immediate patching is not possible, Atlassian recommended disconnecting instances exposed to the internet, regardless of whether they require user authentication. Its alternative measures use rules in a web application firewall, Tomcat RewriteValve or Bitbucket's urlrewrite.xml file to reject directory traversal requests.

Security teams were also advised to check access logs for traversal patterns, first decoding request lines up to twice to account for double-encoded characters.

More in Tech

All Tech

Latest news

All latest