Atlassian patches critical unauthenticated file access bug across eight Data Center products

Atlassian disclosed CVE-2026-21589, a critical arbitrary file access vulnerability rated 9.3, affecting eight Data Center products including Bamboo, Bitbucket, Confluence, Crowd, Crucible, Fisheye, Jira Service Management, and Jira Software. The flaw can be exploited without authentication or user interaction, allowing attackers to read files in web application root directories and potentially use path traversal to reach restricted files. Atlassian advised customers to patch immediately or isolate exposed instances, and said it has not found evidence of exploitation in its already-patched cloud services.
EXPANDED:
The affected lineup includes Bamboo, Bitbucket, Confluence, Crowd, Crucible, Fisheye, Jira Service Management, and Jira Software Data Center. The 9.3-rated flaw lets unauthenticated users read files from top-level web application folders. Path traversal may reach restricted locations, but attackers need precise filenames and locations, and no directory listing is possible. Atlassian says cloud versions are fixed and no exploitation evidence has surfaced there.
Temporary mitigations include WAF or proxy rules, Tomcat RewriteValve changes for several products, and urlrewrite.xml edits for Bitbucket, followed by node restarts. Atlassian calls these limited and not replacements for patching. It cannot confirm whether a given organization's instances were compromised, advising security teams