Australian collaboration vendor Atlassian has released fixes for a critical vulnerability affecting eight of its self-hosted Data Centre products, including Bitbucket, Confluence, Jira Software and Bamboo. The flaw, tracked as CVE-2026-21589, allows unauthenticated attackers to read files from the web application root of affected products.
Vulnerability Details
The vulnerability is rated 9.3 out of 10.0 on the CVSS 4.0 scale and affects multiple Atlassian Data Centre products, including Bitbucket Data Centre, Confluence Data Centre, Jira Service Management Data Centre, Jira Software Data Centre, Bamboo Data Centre, Crowd Data Centre, Crucible, and Fisheye. According to Atlassian, exploitation requires prior knowledge of the target file's exact name and path, and the flaw does not allow attackers to enumerate or list directory contents.
Exploitation Attempts
Exploitation attempts have been detected within two hours of public details being released, with a total of 15 attempts detected from three unique IP addresses located in Japan and the U.S. Atlassian recommends removing instances from the public internet, applying a Web Application Firewall (WAF) rule, blocking requests using Tomcat's RewriteValve, or adding a new rule to urlrewrite.xml as temporary mitigation measures.
Practical Response
To address the vulnerability, affected organisations should immediately patch their Atlassian Data Centre products to the latest fixed releases. Alternatively, temporary mitigation measures can be applied, such as removing instances from the public internet or applying a WAF rule. Organisations should also monitor their access logs for suspicious activity and verify that the patches have been successfully applied.
Talk to Podium IT
Need a clear next step?
Send a secure enquiry and tell us what you are planning. Please do not include passwords, patient information or other sensitive data.
General information only. It is not legal, privacy or compliance advice; requirements should be assessed for your organisation.
