FORSMILE
JA
セキュリティ2026/10/07

[Urgent] Atlassian Data Center CVE-2026-21589: All Versions Affected — Update, or Block ".." in URLs at the WAF

An unauthenticated file-access flaw (CVE-2026-21589) in Atlassian Data Center products such as Confluence, Jira and Bitbucket was published on 5 October. Atlassian rates it CVSS v4.0 9.3 (CRITICAL) and fixed versions are out. The advisory does not report exploitation. Update, or if you cannot yet, apply the official WAF or server-side mitigation that blocks URLs containing "..".

← Back to Blog

An unauthenticated attacker can read files in the web root of Atlassian Data Center products (CVE-2026-21589). It affects the Data Center editions of Confluence, Jira Software, Jira Service Management, Bitbucket, Bamboo, Crowd, Crucible and Fisheye. In its advisory of 5 October 2026 (US time), Atlassian says every version before the fixed versions is affected.
Atlassian Cloud has already been patched and needs no action. Only Data Center instances you run yourself are affected.

First, what is known and what is not. Atlassian rates it CVSS v4.0 9.3 (CRITICAL). This is Atlassian's own assessment; NVD (NIST) had not yet scored it when I checked on 7 October. On exploitation, the advisory says nothing about Data Center, and says for Cloud that "no evidence of exploitation was found". It is not in the CISA KEV catalog either, in the copy I fetched on 7 October (dated 4 October).
An attack needs the exact name and path of the target file. Atlassian says the flaw cannot be used to list directories. It also says that "in some configurations there may be sensitive files that increase your risk".

⚠ CVE Score — 最高危険度 / CRITICAL
9.3CRITICALCVSS v4.0CVE-2026-21589

What to do now

  • ✓First, list the Data Center products you run yourself. Not only Confluence, Jira and Bitbucket: Bamboo, Crowd, Crucible and Fisheye are affected too. If you only use Atlassian Cloud, no action is needed
  • ✓Update to a fixed version: Bitbucket 9.4.26 / 10.2.8 / 10.5.1, Confluence 9.2.26 / 10.2.19, Jira Software 9.12.40 / 10.3.26 / 11.3.12, Jira Service Management 5.12.40 / 10.3.26 / 11.3.12, Bamboo 10.2.24 / 12.1.12, Crowd 6.3.7 / 7.0.3 / 7.1.7 / 7.2.4, and Crucible and Fisheye 4.9.15. Atlassian recommends the fixed long-term support (LTS) version or later
  • ✓If you cannot update right away, take the instance off the internet. Atlassian says to remove it from the internet until you can patch or mitigate, if possible. It asks that internet-facing instances be restricted from external access even if they require user login
  • ✓If you cannot take it offline, apply the official mitigation. There is a way to block URLs containing ".." at a WAF or reverse proxy, and ways to block them in each product's own configuration (next section). Copy the configuration text straight from the Atlassian advisory
  • ✓Check your access logs. Atlassian says it cannot tell whether your instances were affected and asks your security team to check the logs. How to search is in a section below

Affected products and fixed versions (from the Atlassian advisory)

  • ▸Bitbucket Data Center: fixed in 9.4.26, 10.2.8, 10.5.1
  • ▸Confluence Data Center: fixed in 9.2.26, 10.2.19
  • ▸Jira Software Data Center: fixed in 9.12.40, 10.3.26, 11.3.12
  • ▸Jira Service Management Data Center: fixed in 5.12.40, 10.3.26, 11.3.12
  • ▸Bamboo Data Center: fixed in 10.2.24, 12.1.12
  • ▸Crowd Data Center: fixed in 6.3.7, 7.0.3, 7.1.7, 7.2.4
  • ▸Crucible and Fisheye: both fixed in 4.9.15
  • ▸The advisory says all versions before the fixed versions are affected. The NVD description also lists the version in which the flaw was introduced for each product (for example Bitbucket 4.6.0 or later, Confluence 5.10.0 or later, Jira Software 7.1.0 or later)
  • ▸Under Atlassian's current policy, critical security fixes are backported and binary patches are no longer released. You install a maintenance release of a fixed version (from the Atlassian advisory)

If you cannot update: the three official mitigations

Atlassian gives three methods. All of them block URLs where ".." sits right next to "/", a backslash, or "::". URL-encoded forms (such as %2e%2e) are covered as well. The regular expression and rule text are long, and one wrong character can make them ineffective, so I do not reproduce them here. Copy the code from the advisory as it is.

  • ▸Method 1 (all products): add a rule at your WAF or proxy (reverse proxy, AWS WAF, Cloudflare and so on) that blocks URLs matching the regular expression in the advisory
  • ▸Method 2 (Confluence, Jira, Jira Service Management, Bamboo, Crowd): enable Tomcat's RewriteValve and add the blocking rules to rewrite.config under WEB-INF. Back up first, then stop each cluster node, configure it, and restart it, one node at a time
  • ▸Method 3 (Bitbucket only): add the blocking rule at the top of app/WEB-INF/urlrewrite.xml in the installation directory and restart. The same change is needed on mirrors and mirror farm nodes
  • ▸Whichever you use, test afterwards that URLs with adjacent ".." are really blocked, including the encoded patterns (Atlassian tells you to test)

How to look for signs of compromise (official guidance)

Atlassian gives two ways to search the access logs.
(1) URL-decode each request line (up to two passes), then look for ".." next to "/", a backslash, or "::".
(2) Search the raw, non-decoded log lines directly with the regular expression in the advisory.
Neither Atlassian nor I could find a published list of indicators of compromise, such as file names, for this flaw. If the logs show a match, work with your security team to establish which files may have been read. It also helps to check whether configuration files or credentials sit under the same web root

Exploitation: what is known and what is not

What is known. Atlassian's advisory gives the flaw, the fixed versions and the mitigations. For Cloud it says "no evidence of exploitation was found". It was not in KEV in the copy I fetched on 7 October.
What is not known. The advisory does not say whether Data Center instances have been attacked. BleepingComputer reports that Atlassian said it has no evidence of exploitation at present, but I could not confirm Atlassian's own statement in a primary source. The advisory is brand new, and I found no material on third-party verification or exploit code. "Not confirmed exploited" is not the same as "safe". The flaw is reachable over the network without authentication and fixed versions exist, so update internet-facing servers soon.

What I could not confirm

  • ▸The NVD assessment. When I checked on 7 October, NVD showed "Awaiting Analysis" and had no NIST CVSS. The 9.3 (v4.0, CRITICAL) in this article is the value Atlassian registered as the CNA. The number may change once NIST scores it
  • ▸Which files can be read. Atlassian only says sensitive files may exist in some configurations; it gives no specific files or per-product impact
  • ▸Whether it is exploited, and indicators of compromise. As above, the official material has no statement
  • ▸A JVN entry. I had not checked JVN for this CVE when I wrote this. The Atlassian advisory is the reference for fixed versions and mitigations

Share these three lines

  • ▸Atlassian Data Center products (Confluence, Jira, Bitbucket, Bamboo, Crowd, Crucible, Fisheye) have an unauthenticated file-read flaw (CVE-2026-21589). Atlassian rates it 9.3 (CRITICAL). Cloud is already patched
  • ▸★If you run it yourself, update to a fixed version. If you cannot, take it off the internet or use the official WAF or server-side mitigation that blocks URLs containing ".."
  • ▸The official material does not report exploitation, but that does not mean safe. Check the access logs the official way

Pages this article is based on

Related articles