Atlassian has disclosed CVE-2026-21589, a critical arbitrary file access vulnerability affecting Confluence Data Center and seven other self-managed products. The advisory, published on October 5, 2026, warns that every version of the affected software is exposed and urges administrators to act right away, either by upgrading or by putting temporary safeguards in place.
Beyond Confluence Data Center, the flaw reaches Bitbucket Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. Atlassian is tracking the issue under BSERV-20604, CONFSERVER-104488, JSDSERVER-16809, JRASERVER-79546, BAM-26567, CWD-6610, CRUC-8741 and FE-7583.
Which Atlassian Products CVE-2026-21589 Affects
The bug lets an attacker with no login read specific files inside the web application’s root directory. There is a catch for attackers: they must already know a file’s exact name and location, since the weakness does not reveal or list directory contents. Even so, Atlassian notes that some setups may store sensitive files there, which raises the stakes.
Atlassian scores CVE-2026-21589 at 9.3, placing it in the Critical band, using the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H. The company describes this as its own internal assessment and advises organizations to judge how it applies to their environments.
Cloud users are not affected. Atlassian says its Cloud products have already been patched, its investigation found no sign of exploitation there, and Cloud customers need to take no action.
Patched Versions for Confluence and Other Atlassian Tools
The primary fix is an upgrade. Atlassian recommends moving each installation to a fixed release, ideally the fixed LTS version or the newest available build.

| Product | Fixed versions |
| Bitbucket Data Center | 9.4.26, 10.2.8, 10.5.1 |
| Confluence Data Center | 9.2.26, 10.2.19 |
| Jira Service Management Data Center | 5.12.40, 10.3.26, 11.3.12 |
| Jira Software Data Center | 9.12.40, 10.3.26, 11.3.12 |
| Bamboo Data Center | 10.2.24, 12.1.12 |
| Crowd Data Center | 6.3.7, 7.0.3, 7.1.7, 7.2.4 |
| Crucible | 4.9.15 |
| Fisheye | 4.9.15 |
Stopgap Measures Against CVE-2026-21589
Teams that cannot upgrade yet should take instances offline from the internet where possible, including those protected by user authentication. Atlassian then offers three mitigations, all built on one regex meant to block “..” sitting directly next to /, , or ::, including URL-encoded forms:
(?is).*(?:/|\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:.|%(?:25)*2e){2}(?:/|\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).*
- Web Application Firewall rule (all products): block any URL matching the pattern in a WAF or proxy such as AWS WAF, Cloudflare or a reverse proxy, then test that encoded variants are caught.
- Tomcat RewriteValve (Confluence, JSM, Jira, Bamboo, Crowd): after a backup, shut down each node, enable the valve in server.xml (Crowd may use crowd.xml), and add or append a rewrite.config file in the product’s WEB-INF directory. It checks both the normalized request path and the raw URI, returning a forbidden response. Restart the node afterward.
- urlrewrite.xml rule (Bitbucket only): back up, then place the rule at the top of /app/WEB-INF/urlrewrite.xml on every node, mirror and mirror farm node, returning a 404 via /mvc/error404. Restart Bitbucket.
Checking Confluence Logs for Signs of Compromise
Atlassian says it cannot confirm whether any customer instance has been hit and advises bringing in local security teams. Investigators can URL-decode each access-log request up to twice and search for “..” next to /, , or ::, or run the regex directly against raw log lines.
Under Atlassian’s security bug fix policy, critical fixes are backported as new maintenance releases instead of binary patches. Customers can subscribe to alert emails at my.atlassian.com/email and raise questions through support.atlassian.com.

