Atlassian Patches a File Access Flaw in Every Version of Eight Self-Hosted Products

Atlassian published fixes on Oct. 5, 2026, for a flaw in eight of its self-hosted products that the company says lets an attacker with no account on the system read certain files off the server. Every version of all eight is affected.
The eight are Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye, all of them versions a customer runs on its own machines. Atlassian said its hosted Cloud products have already been patched, that its investigation found no evidence the flaw had been used against them, and that Cloud customers need do nothing.
The flaw is tracked as CVE-2026-21589. Atlassian calls it an arbitrary file access vulnerability, meaning files can be read off a running installation, and says it reaches specific files inside the web application root directory of an affected system. The advisory says anyone attempting it has to know the exact name and path of the file in advance, and that the flaw cannot be used to list a directory's contents. The company said some setups hold sensitive files in that location, which raises the risk.
Atlassian rates the severity Critical, at 9.3, and says that figure is its own internal assessment, which customers should judge against their own environment.
Fixed versions are listed product by product in the advisory, which also carries interim mitigation steps for administrators who cannot upgrade straight away and advises keeping affected instances off the public internet until one or the other is in place.
Atlassian said it cannot confirm whether any individual installation has been affected, and told customers to have their own security teams look for evidence of compromise. The fixes arrive as maintenance releases: under the company's security bug fix policy, critical security fixes are back-ported to supported versions, and binary patches are no longer issued.
