Executive Summary

On October 5th, 2026, Atlassian disclosed a critical vulnerability in eight of its self-hosted products, including Crowd, Jira, Confluence, and Bitbucket Data Center. Tracked as CVE-2026-21589, the flaw lets an unauthenticated, remote attacker read files in the application's web root with a maliciously crafted request. All self hosted versions before Atlassian's fixed releases are affected, including end-of-life versions.

These products hold source code, documentation, and identity data for many organizations. Atlassian notes that some configurations may store sensitive files in the web root. Public research shows that one such file can expose Atlassian Crowd credentials, and an attacker who can reach Crowd can use them to create administrator accounts.

At the time of writing, exploitation in the wild has not been confirmed however on October 6th, 2026, the cybersecurity research company watchTowr published enough technical details about the flaw to create a proof-of-concept. Given the release of these details, Beazley Security recommends affected organizations apply available fixes as soon as possible on self hosted implementations.

Affected Systems or Products

Product

Affected Versions

Fixed Versions

Bitbucket Data Center

4.6.0 and later, before the fixed release for each branch

9.4.26, 10.2.8, 10.5.1

Confluence Data Center

5.10.0 and later, before the fixed release for each branch

9.2.26, 10.2.19

Jira Software Data Center

7.1.0 and later, before the fixed release for each branch

9.12.40, 10.3.26, 11.3.12

Jira Service Management Data Center

3.1.0 and later, before the fixed release for each branch

5.12.40, 10.3.26, 11.3.12

Bamboo Data Center

7.0.1 and later, before the fixed release for each branch

10.2.24, 12.1.12

Crowd Data Center

2.11.0 and later, before the fixed release for each branch

6.3.7, 7.0.3, 7.1.7, 7.2.4

Crucible

All versions before 4.9.15

4.9.15

Fisheye

All versions before 4.9.15

4.9.15

Mitigations / Workarounds

Atlassian recommends upgrading every affected instance to a fixed long-term support (LTS) release or later. Atlassian also states that its temporary mitigations are limited and do not replace patching. Organizations still running affected self-hosted products should move to a fixed Data Center release.

Beyond Atlassian's guidance, Beazley Security recommends that any instances authenticated through Crowd and were reachable from the internet while vulnerable rotate the Crowd application password after patching.

If patching cannot be immediately applied, the following may help to temporarily reduce risk on self-hosted implementations:

  • Take internet-facing instances offline where possible. Atlassian recommends restricting external network access to any instance reachable from the public internet until it is upgraded or a blocking rule is in place. This includes instances that require a login.

  • Apply Atlassian's web application firewall (WAF) or reverse proxy rule. Atlassian supplied a regex filter that blocks request URLs containing .. next to /, \, or ::, including URL-encoded forms. The rule reportedly works for all eight products affected.

  • For Confluence, Jira Software, Jira Service Management, Bamboo, and Crowd, apply Atlassian's Tomcat RewriteValve rule on each node. Each node must be shut down, changed, and restarted.

  • For Bitbucket, add Atlassian's rule to urlrewrite.xml on every node, mirror, and mirror farm node, then restart.

  • Where Jira, Confluence, Bitbucket, or Bamboo authenticate through Crowd, limit access to Crowd to the IP addresses of the connected application servers.

In-depth details on how to implement these mitigations are available in Atlassian's advisory.

Patches

Atlassian has released fixed versions of all eight affected products and recommends upgrading to a fixed LTS release or later. Details are in Atlassian's security advisory for CVE-2026-21589, titled "Arbitrary File Access Vulnerability impacts Multiple Products".

Atlassian has already patched its affected Cloud products, and Cloud customers require no action.

Threat Intelligence

At the time of writing, no threat actor activity or campaigns have been linked to CVE-2026-21589. Atlassian has patched its affected Cloud products and reports no evidence of exploitation there. Atlassian says it cannot confirm whether self-hosted instances have been affected.

Technical Details

Atlassian describes CVE-2026-21589 as an arbitrary file access flaw within the web application root directory. According to the Atlassian advisory the flaw does not allow directory listing, so the attacker must already know the exact name and path of the target file.

watchTowr researchers reproduced the vulnerability and found that attackers can use specially crafted ..:: sequences to bypass path filtering in Atlassian's web resource handling. This allows an unauthenticated attacker to read files within affected applications. The vulnerability does not allow attackers to read files outside the application directory, but files stored within it may contain sensitive information.

watchTowr demonstrated that Jira environments integrated with Atlassian Crowd could expose crowd.properties, which may contain the Crowd server address and application credentials. If the Crowd server is also reachable from the internet, these credentials could potentially be used to create an account and grant it Jira administrator privileges. watchTowr has released public proof-of-concept code demonstrating the attack.

For detection, Atlassian recommends reviewing web access logs for suspicious path traversal sequences, particularly ..:: appearing in requests to /download/resources/. Defenders should prioritize matching requests that received successful HTTP responses, as these may indicate that a file was successfully retrieved.

How Beazley Security is responding

Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.

We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.

If you believe your organization may have been impacted by this vulnerability and need support, please contact our Incident Response team.