Triskele Labs Blog

Atlassian Data Center Pre-Auth File Read (CVE-2026-21589) - Patch Now

Written by Adam Skupien, Vulnerability Security Analyst | Oct 7, 2026, 5:26:07 AM

Published: Wed 07 October 2026

Prepared by: Adam Skupien, Vulnerability Security Analyst

Summary

Atlassian has released an advisory for CVE-2026-21589, a critical (CVSS 9.3) unauthenticated file read vulnerability affecting all Atlassian Data Center products: Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible and Fisheye. A patch is available, and we urge organisations to apply it as soon as possible, ahead of their normal patch cycle. Atlassian Cloud is not affected.

Vulnerability details

  • CVE: CVE-2026-21589
  • Severity: Critical, CVSS 4.0 score 9.3 (Atlassian)
  • Type: Arbitrary file read via path traversal, no authentication required
  • Advisory released: 5 October 2026
  • Exploitation: No in-the-wild exploitation reported at time of writing

An unauthenticated attacker can read files within the application web root, including WEB-INF configuration files. Atlassian notes the attacker must know the exact file path, but the locations of sensitive configuration files are documented in Atlassian's public product documentation, so this is not a meaningful barrier. Directory listing is not possible.

Affected systems

All versions prior to the fixed releases below of:

  • Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1
  • Confluence Data Center: 9.2.26, 10.2.19
  • Jira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12
  • Jira Software Data Center: 9.12.40, 10.3.26, 11.3.12
  • Bamboo Data Center: 10.2.24, 12.1.12
  • Crowd Data Center: 6.3.7, 7.0.3, 7.1.7, 7.2.4
  • Crucible and Fisheye: 4.9.15

Impact

Sensitive configuration files may be exposed, and watchTowr Labs has demonstrated this can lead to full compromise. For example, Jira instances integrated with Crowd store the Crowd application credentials in plaintext in WEB-INF/classes/crowd.properties. An attacker who obtains them can create users and grant administrator access, unless Crowd access is restricted by IP allowlist.

Mitigation actions

  1. Patch all affected instances to a fixed version as soon as possible, outside the normal patch cycle if necessary.
  2. If you cannot patch immediately:
    • Remove internet access to the instance, or restrict it to trusted networks.
    • Apply the Atlassian-provided WAF/proxy rule (or product-specific rewrite rule) to block .. adjacent to /, \ or ::.
  3. After patching, rotate any credentials stored in WEB-INF configuration files (for example Crowd application credentials) on instances that were internet-facing and unpatched. Treat this as urgent if log review finds matching requests.

Full instructions and rule syntax are in the Atlassian advisory.

Detection capabilities

  • Check your Atlassian Data Center versions against the fixed versions above.
  • Search web access logs for .. adjacent to /, \ or :: (URL-decode up to two passes first).
  • Review Crowd, Jira and Confluence for unexpected new accounts or administrator group changes.
  • Review Crowd logs for authentication by application accounts from unexpected source IPs.
  • Optional: if you cannot easily confirm your versions, watchTowr Labs has published a detection tool for Jira, Confluence and Bitbucket. It is third-party code that sends requests to the target, so review it first and run it only against systems you own

MDR customers: Triskele Labs will continue tuning detections and analysing IOCs, as they become publicly available, for behaviours consistent with the exploitation of CVE-2026-21589 across supported log sources.

Vulnerability Management customers: Environments will be assessed for vulnerable versions of the Atlassian Data Center products affected by CVE-2026-21589. Any findings will be communicated through priority channels.

References