Vulnerability Management, Application security, Data Security, DevOps

Atlassian warns of critical arbitrary file access vulnerability in self-hosted products

Atlassian has issued a warning to its customers regarding a critical vulnerability, identified as CVE-2026-21589, that affects multiple self-hosted Data Center products. This security flaw enables arbitrary file access, posing a significant risk to organizations utilizing affected versions of Confluence, Jira, and Bitbucket, as detailed in Bleeping Computer.

The vulnerability, CVE-2026-21589, allows an unauthenticated attacker to access specific files within the web application's root directory, provided they know the exact file name and path. Atlassian has released updated versions for Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye to address this issue. While cloud customers are unaffected due to automatic patching, administrators of self-hosted instances are urged to apply the updates immediately.

Temporary mitigations, such as restricting external network access, implementing web application firewall rules, or using URL rewrite rules, are available for those unable to patch immediately. Atlassian has stated there is no current evidence of exploitation but advises reviewing access logs for suspicious activity. Organizations using self-hosted instances are encouraged to consult their internal security teams.

Source: Bleeping Computer

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds