DevSecOps, Third-party code, Patch/Configuration Management

Critical Atlassian flaw exposes files across eight products

The homepage of Atlassian website is displayed on a PC.

Atlassian on Oct. 5 warned customers to patch a critical CVSS 9.3 arbitrary file access vulnerability in eight of its development products.

The bug — CVE-2026-21589 — lets an unauthenticated attacker access specific files within the web application directory root in affected versions.

Atlassian shared in a blog post that all versions of the following products are affected:

  • Bitbucket Data Center
  • Confluence Data Cente
  • Jira Service Management Data Center
  • Jira Software Data Center
  • Bamboo Data Center
  • Crowd Data Center
  • Crucible
  • Fisheye

Seemant Sehgal, chief executive officer at BreachLock, said unauthenticated access across eight products at CVSS 9.3 gives an attacker "read access" to configuration files and other sensitive artifacts sitting in web application roots.

Because these products hold source code, build infrastructure, identity, and documentation for most engineering organizations, Sehgal said that’s where the real impact lies. The requirement that an attacker know the exact file path is less protective than it sounds because those paths are documented in open source code and prior CVE write-ups going back years, explained Sehgal.

“Teams running affected versions should treat this as high priority because the follow-on access can compound quickly, where a configuration file leak can expose credentials used across downstream CI/CD systems and connected identity infrastructure,” said Sehgal.

Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs, added that many teams use Atlassian to keep the machinery of software delivery, so he advises treating this as an urgent patching issue.

Krell said the attacker still needs the exact file path and cannot list directories, but that’s limited comfort when the request requires no login. A readable configuration or credential file could deliver a path from self-hosted Jira, Confluence or Bitbucket into code repositories and build systems, said Krell.

“Cloud customers have already been patched,” said Krell. “Self-hosted teams should upgrade now. If that’s not immediately possible, take the instance off the public internet or block traversal patterns at a web application firewall or reverse proxy, then check the logs for attempted exploitation. A workaround buys time. It does not fix the vulnerable code.”

Aaron Beardslee, manager of threat research at Securonix, explained that Atlassian sits deep inside the way many companies build and run software: Jira tracks development work, Bitbucket manages code, Bamboo supports builds and deployments, and Confluence often holds the documentation around those systems. Crowd, Fisheye and Crucible extend that footprint into identity, code search and review.

“CVE-2026-21589 affects versions across all eight products, so security teams need to know where those systems are running and what information sits around them,” said Beardslee.

Beardslee added that if it’s not possible to do an immediate upgrade, Atlassian recommended removing the instance from the internet or restricting external access. Atlassian has also published temporary mitigations, including a WAF or reverse-proxy rule for all affected products, Tomcat RewriteValve configurations for several products, and a separate urlrewrite.xml rule for Bitbucket.

“Those controls buy time,” said Beardslee. “They do not replace patching. The exploitation statement needs to be read carefully. Atlassian says its investigation found no evidence of exploitation in the affected cloud products. It does not make the same claim for customer-managed instances, and it says it cannot confirm whether any individual customer systems were affected.”

Steve Zurier
Steve Zurier has been a freelance writer and editor for SC Media since 2012. Now, Zurier writes daily news stories and edits SC Media’s Perspectives columns. A long-time member of the tech press, Zurier lives in Columbia, MD. During off-hours, Steve moonlights as an upright bassist for jazz and klezmer bands around the Baltimore/DC area.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds