← All security news

Critical Atlassian Flaw Let Anyone Read Files From Jira and Confluence

A stack of file icons next to an open padlock, representing an unauthenticated path-traversal flaw that let attackers read files from Atlassian's self-hosted products

Atlassian has patched a critical path-traversal flaw, tracked as CVE-2026-21589, that let anyone on the internet — no login required — pull specific files out of eight widely used Atlassian products, as long as they already knew the exact file name and path to ask for. The bug carries a CVSS score of 9.3, Atlassian's top severity band, and affects the self-hosted Data Center and Server editions of Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye. Cloud-hosted versions were already fixed before customers were even told about the issue, and Bitbucket Cloud was never affected at all. Atlassian says it has no evidence of the flaw being used in attacks so far — but it also says it "cannot confirm" that any individual customer's server hasn't already been hit, which is a blunt way of saying it can't rule it out.

The flaw doesn't let an attacker browse a server's files freely; it requires knowing in advance exactly which file to request. In practice, that still covers a meaningful set of configuration and application files whose names and locations are predictable across installs, which is why researchers are treating it as a genuine reconnaissance and data-exposure risk rather than a theoretical one. Atlassian released fixed versions for all eight products on 6 October 2026, alongside temporary mitigation rules (blocking the request pattern at a reverse proxy or web application firewall) for teams that can't patch right away.

What this means for your business

If your business — or an IT provider working on your behalf — runs any self-hosted Atlassian product, most commonly Jira for project tracking or Confluence for internal documentation, check this week whether it's a Data Center or Server install and, if so, whether it has been updated to the version Atlassian released on 6 October. Atlassian Cloud customers, recognisable by an atlassian.net web address, don't need to do anything here; the cloud side was already fixed before this was disclosed. If you're not sure which type your business runs, that's worth finding out regardless — it's exactly the kind of detail that gets lost once a tool like Jira has been running quietly in the background for years.

More broadly, this is a reminder that internal tools — the project tracker, the wiki, the build server — tend to go unpatched longest precisely because nobody notices they're out of date the way they'd notice a broken public website. If no one on your team has a routine for checking vendor security bulletins on the internal software you run, that's a gap worth closing before the next one of these lands.

Questions about your own setup? contact@techleetsolutions.com
Sources: BleepingComputer, The Hacker News, Atlassian advisory (CONFSERVER-104488)