MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-07 · via InfoWorld

Atlassian patches critical unauthenticated file access bug across eight Data Center products

Image via InfoWorld
Image via InfoWorld

Atlassian disclosed CVE-2026-21589, a critical arbitrary file access vulnerability rated 9.3, affecting eight Data Center products including Bamboo, Bitbucket, Confluence, Crowd, Crucible, Fisheye, Jira Service Management, and Jira Software. The flaw can be exploited without authentication or user interaction, allowing attackers to read files in web application root directories and potentially use path traversal to reach restricted files. Atlassian advised customers to patch immediately or isolate exposed instances, and said it has not found evidence of exploitation in its already-patched cloud services.

Expanded Detail

EXPANDED:

The affected lineup includes Bamboo, Bitbucket, Confluence, Crowd, Crucible, Fisheye, Jira Service Management, and Jira Software Data Center. The 9.3-rated flaw lets unauthenticated users read files from top-level web application folders. Path traversal may reach restricted locations, but attackers need precise filenames and locations, and no directory listing is possible. Atlassian says cloud versions are fixed and no exploitation evidence has surfaced there.

Temporary mitigations include WAF or proxy rules, Tomcat RewriteValve changes for several products, and urlrewrite.xml edits for Bitbucket, followed by node restarts. Atlassian calls these limited and not replacements for patching. It cannot confirm whether a given organization's instances were compromised, advising security teams

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at InfoWorld →
Related stories
Attackers Begin Exploiting Critical Atlassian Vulnerability Within Hours of Patch Release · Cybersecurity
SonicWall Fixes Maximum-Severity SSRF Bug in SMA1000 Remote Access Appliances · Cybersecurity
Enterprise Solutions Enable Unified Security Management for Distributed Data Centers · Cybersecurity
No Fix Yet for LMCache Flaw That Allows Unauthenticated Remote Code Execution · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Atlassian’s critical flaw turns eight enterprise products into one big security problem.” Browse more stories.