Skip to content
See the World Through ScienceA project of ALLATRA

Atlassian Patches a File Access Flaw in Every Version of Eight Self-Hosted Products

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

A yellow heritage corner building on a city street with a blue ATLASSIAN sign across its facade.
The company's offices, in an older corner building downtown. The eight products patched are the self-hosted editions, which customers run on their own servers rather than Atlassian's (illustrative)."Atlassian, Sydney" by avlxyz, via flickr, CC-BY-SA-2.0

Atlassian published fixes on Oct. 5, 2026, for a flaw in eight of its self-hosted products that the company says lets an attacker with no account on the system read certain files off the server. Every version of all eight is affected.

The eight are Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye, all of them versions a customer runs on its own machines. Atlassian said its hosted Cloud products have already been patched, that its investigation found no evidence the flaw had been used against them, and that Cloud customers need do nothing.

The flaw is tracked as CVE-2026-21589. Atlassian calls it an arbitrary file access vulnerability, meaning files can be read off a running installation, and says it reaches specific files inside the web application root directory of an affected system. The advisory says anyone attempting it has to know the exact name and path of the file in advance, and that the flaw cannot be used to list a directory's contents. The company said some setups hold sensitive files in that location, which raises the risk.

Atlassian rates the severity Critical, at 9.3, and says that figure is its own internal assessment, which customers should judge against their own environment.

Fixed versions are listed product by product in the advisory, which also carries interim mitigation steps for administrators who cannot upgrade straight away and advises keeping affected instances off the public internet until one or the other is in place.

Atlassian said it cannot confirm whether any individual installation has been affected, and told customers to have their own security teams look for evidence of compromise. The fixes arrive as maintenance releases: under the company's security bug fix policy, critical security fixes are back-ported to supported versions, and binary patches are no longer issued.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Atlassian Patches a File Access Flaw in Every Version of Eight Self-Hosted Products

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.