Critical Atlassian Path Traversal Bug Hits 8 Self-Hosted Products
AI-generated image

Critical Atlassian Path Traversal Bug Hits 8 Self-Hosted Products

Atlassian patched a critical path traversal flaw, CVE-2026-21589, that lets unauthenticated attackers read known files in eight self-hosted Data Center products…

A critical Atlassian path traversal vulnerability, CVE-2026-21589, allows an attacker with no login access to read specific files from eight self-hosted Atlassian Data Center products. A path traversal is a flaw in which a specially built web request uses a file path that reaches outside the intended area. Atlassian disclosed the flaw on October 5 and rated it 9.3 out of 10. The attacker must already know a file's exact name and path and cannot list what the directory holds.

The vulnerable products are Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. These are the Data Center editions, which organizations run on their own servers rather than in Atlassian's cloud. The web application root directory is the folder on the server that holds the web application itself; in some configurations it may contain sensitive files, which raises the risk. Atlassian's cloud products affected by the flaw have already been patched, and cloud customers do not need to take any action.

Atlassian listed fixed versions as of October 6. Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1. Confluence Data Center: 9.2.26, 10.2.19. Jira Software Data Center: 9.12.40, 10.3.26, 11.3.12. Jira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12. Bamboo Data Center: 10.2.24, 12.1.12. Crowd Data Center: 6.3.7, 7.0.3, 7.1.7, 7.2.4. Crucible: 4.9.15. Fisheye: 4.9.15. All versions of these eight products before the fixed versions are affected, and Atlassian says that may include versions that have reached end of life. It recommends upgrading to a fixed long-term support (LTS) version or later.

The advisory and the CVE record do not fully agree on every number. For Crowd's 7.1 branch, the ticket's fix version field said 7.1.7, while a table in the same ticket showed 7.1.6, which the ticket also listed as an affected version. The CVE record Atlassian filed gave different numbers for two products. For Crowd it listed 7.1.1, which the Crowd 7.1 release notes date to November 27, 2025, more than 10 months before the flaw was disclosed. For Bamboo one field said 10.2.4, while the record's own description said 10.2.24. The CVE record also listed the Server editions, Atlassian's older self-hosted line, which the advisory did not mention. It marked every version of Bamboo Server, Bitbucket Server, Confluence Server and Crowd Server as affected and listed no fixed versions for them. For Jira Software Server it listed versions from 9.12.40 as unaffected, for Jira Service Management Server from 5.12.40, and for Crucible Server and Fisheye Server from 4.9.15. The record did not say whether Server licenses can run those versions. Crowd has had no Server release since version 5.2 in September 2023, so none of the fixed Crowd versions are Server releases.

Atlassian labels the flaw a path traversal in the CVE record. It describes three temporary blocking rules, which it calls mitigations. All three block requests whose URL contains two dots directly next to a forward slash, a backslash or a double colon, including URL-encoded forms. Which rules apply depends on the product. All eight products can use a rule on a web application firewall (WAF) or reverse proxy that blocks matching URLs. Confluence, Jira Software, Jira Service Management, Bamboo and Crowd can also use a Tomcat RewriteValve rule installed on each node, which must be shut down and restarted. Bitbucket can use a rule in urlrewrite.xml applied to every node, mirror and mirror farm node, followed by a restart. Crucible and Fisheye have only the first option. The advisory gives the rule and the file changes for each one. Atlassian says in its product tickets that these mitigations are limited and not a replacement for patching.

Atlassian said its affected cloud products have been patched and its investigation has not found evidence of exploitation. Bitbucket Cloud is not affected. The advisory does not say whether attacks on self-hosted instances have been seen. It tells customers that Atlassian cannot confirm if their instances have been affected by this vulnerability. Customers should have their security teams search access logs. One method is to URL-decode each request line, up to two times, and look for two dots directly next to a forward slash, a backslash or a double colon. The other is to run Atlassian's block pattern over the raw log lines. The advisory does not explain how to distinguish a failed attempt from a request that returned a file, or what else a customer who encounters such requests should do after upgrading.

Attackers have exploited this kind of flaw in an Atlassian product before. CVE-2021-26086 is a path traversal vulnerability in Jira Server and Data Center that allows remote attackers to read specific files. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its catalog of known exploited vulnerabilities on November 12, 2024. The 9.3 rating for CVE-2026-21589 uses version 4.0 of the Common Vulnerability Scoring System (CVSS) and is Atlassian's own. The company tells customers to judge how the score applies to their environment. The score rates the flaw as reachable over the network without privileges or user action, with high effect on the vulnerable system's confidentiality, no effect on its integrity or availability, and high effect on other systems. Atlassian does not identify the sensitive files or the configurations that contain them, nor does it explain the high rating for other systems. Teams that run self-hosted Atlassian products may also benefit from a security-first IT review, such as the infrastructure and consulting work offered by AEU-I, to check that public-facing applications are patched and access is restricted.

How to Protect Yourself

  1. If your company runs Atlassian software such as Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible or Fisheye on its own servers, ask your IT team today whether the update from Atlassian has been installed.
  2. Until the update is in place, make sure the Atlassian website is not reachable from the public internet; keep it on your office network only.
  3. Ask your IT team to look at the web server logs for web addresses that contain two dots right next to a slash or backslash, which may show someone tried to break in.
  4. If your company uses a web application firewall, ask them to turn on Atlassian's temporary blocking rule that stops those dangerous web addresses.
  5. Treat any public-facing Atlassian login page as urgent and do not wait; attackers only need a known file path, not a password.

Vulnerabilities & Fixes

Terms Explained

  • path traversal A type of weakness that lets a specially crafted web request reach files outside the intended area, by using file path tricks.
  • web application root directory The folder on a server that holds the web application itself, where program files and sometimes sensitive configuration files are stored.
  • reverse proxy A server that sits in front of web applications and can inspect or block incoming requests before they reach the app.
  • web application firewall (WAF) A security filter that watches traffic to a website and blocks requests that look like attacks.
  • CVSS A standard scoring system that rates how serious a security flaw is, from 0 to 10.
  • long-term support (LTS) A software version that the vendor promises to keep fixing and supporting for a long time, often for years.

Related AEU services

  • AEU Data Cloud and data infrastructure