Atlassian has disclosed CVE-2026-21589, a critical arbitrary-file-access vulnerability affecting eight self-hosted Data Center products. The vendor rated the issue 9.3 under CVSS v4.0. An unauthenticated attacker must know a target file’s exact path, but could read files from the web application root when the affected conditions are present.

The affected product list includes Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye Data Center. Atlassian has published fixed versions for each product family; its cloud products were patched, while self-managed administrators need to evaluate and upgrade their own instances.

Teams that cannot upgrade immediately should reduce public exposure and apply Atlassian’s documented temporary blocking rules where appropriate. Administrators should also review access logs for encoded and decoded path-traversal patterns, then treat the mitigations as temporary controls rather than a replacement for patching.

Source: The Hacker News coverage of Atlassian’s advisory

By Allan