Trusence Every claim has a source
Last updated 6 October 2026 Search Türkçe
← All stories
Security

Atlassian patches critical file-access flaw in Jira, Confluence and Bitbucket

Cloud users are unaffected, while self-hosted administrators are being told to update immediately.

Atlassian has issued patches for CVE-2026-21589, a critical arbitrary file-access flaw in several self-hosted Data Center products including Jira, Confluence, and Bitbucket. The bug lets an unauthenticated attacker read specific files in an app’s web root, but only if they already know the exact filename and path. Fixes are available in released versions for Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye, and Atlassian is telling administrators to update immediately. Cloud customers do not need to act, and Atlassian says it has no evidence the issue is being exploited, though it recommends checking logs and using temporary network or WAF-style mitigations if patching must wait.

Why it matters

The risk is narrower than a general file leak, but it still affects self-hosted instances that expose the right paths. For those operators, the practical effect is immediate patching; for cloud customers, Atlassian says no action is needed. Atlassian also says it has no evidence of active exploitation, which gives administrators some time to verify and update, but not to delay.

Sources

  • BleepingComputer