Atlassian Warns Data Centre Admins To Patch Critical File Access Flaw
Atlassian is urging Data Centre customers to patch CVE-2026-21589, a critical flaw that can let unauthenticated attackers read specific web-root files.

Help Net Security reported that Atlassian administrators face an immediate patching deadline for a critical Data Centre vulnerability that can expose specific files to unauthenticated attackers.
CVE-2026-21589 carries a 9.3 CVSS score and spans the company's Data Centre line: Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible and Fisheye deployments are all in scope.
The Oct. 5 advisory uses Atlassian's internal CVSS 4.0 assessment.
The access problem is narrow but serious: an attacker can reach files within the web application root directory, and sensitive files in some configurations could raise the risk.
Exploitation still requires precision.
A successful attempt depends on already knowing the target file's precise path and name, and the weakness does not provide directory listing or enumeration.
That constraint limits broad browsing of affected systems, but it does not remove the exposure for known files on internet-facing deployments.
Atlassian's cloud products are already fixed, cloud customers have no required action, and the investigation has not found exploitation.
The immediate work is instead on self-managed Data Centre installations, where administrators must upgrade each affected product to a fixed version or the latest release.
Network exposure is also part of the response.
Administrators are advised to take affected instances off the internet where possible and restricting publicly reachable instances from external network access until administrators can complete the required action, including systems that still require user authentication.
The company has published three temporary mitigations for teams that cannot complete upgrades immediately.
It also warns that it cannot confirm whether individual customer instances have been affected, leaving security teams to inspect affected environments for evidence of compromise.
The advisory does not identify who discovered the vulnerability or state whether attackers have used it against Data Centre instances.
The practical next step for operators is therefore concrete: patch or isolate the affected products, then review exposed systems for signs that specific files were accessed.




















