Atlassian has published a critical security advisory for its self-hosted Data Center products, including Jira Software, Jira Service Management and Confluence. The flaw, tracked as CVE-2026-21589, lets an attacker who has not logged in read certain files from a server running an unpatched version. Atlassian released the advisory on 5 October 2026 and rates the issue 9.3 out of 10, which it classes as critical.
Teams that use Jira or Confluence in Atlassian's cloud do not need to do anything. Atlassian says its cloud products have already been patched. The work falls on organisations that run Atlassian software on their own servers.
What Atlassian disclosed
According to the Atlassian security advisory, this is an arbitrary file access vulnerability that "allows an unauthenticated attacker to access specific files within the web application root directory in affected versions." Atlassian adds a limit: "Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents."
The advisory lists eight self-hosted products as affected:
- Jira Software Data Center
- Jira Service Management Data Center
- Confluence Data Center
- Bitbucket Data Center
- Bamboo Data Center
- Crowd Data Center
- Crucible
- Fisheye
For the cloud versions, Atlassian states: "Affected Atlassian Cloud products have been patched, and our investigation has not found evidence of exploitation. No Cloud customer action is required."
Why a file read flaw is rated critical
Reading files may sound less serious than taking over a server, but the files inside a web application can hold settings and secrets. Security firm watchTowr, which published a technical analysis on 6 October 2026, says the flaw can expose configuration files. In setups where Jira or Confluence is connected to Atlassian Crowd for sign-in, watchTowr says one of those files holds the Crowd application name and password in plain text, and that an attacker who reads it could go on to gain administrator access. Atlassian's own advisory also warns that "in some configurations, there may be sensitive files present that increase your risk."
watchTowr also published proof-of-concept code and a tool to help defenders detect vulnerable systems. Public exploit code usually shortens the time between disclosure and real attacks, which is one reason to patch quickly.
BleepingComputer, which reported the advisory on 6 October, noted that there was no evidence of active exploitation at the time of writing. Atlassian says it "cannot confirm if your instances have been affected by this vulnerability" and asks customers to involve their own security teams.
Which versions fix it
Atlassian has released fixed versions for each product. The ones most project management teams will care about are:
- Jira Software Data Center: 9.12.40, 10.3.26 or 11.3.12
- Jira Service Management Data Center: 5.12.40, 10.3.26 or 11.3.12
- Confluence Data Center: 9.2.26 or 10.2.19
- Bitbucket Data Center: 9.4.26, 10.2.8 or 10.5.1
The advisory also lists fixes for Bamboo (10.2.24, 12.1.12), Crowd (6.3.7, 7.0.3, 7.1.7, 7.2.4), Crucible (4.9.15) and Fisheye (4.9.15). Atlassian says it does not issue binary patches any more: fixes arrive as new maintenance releases, so patching means upgrading.
What to do now
If your organisation runs Jira, Confluence or another listed product on its own servers, Atlassian's advice is clear:
- Upgrade each affected installation to a fixed version or the latest version.
- Cut off public access until you can upgrade. Atlassian says instances reachable from the internet, "including those with user authentication, should be restricted from external network access until you can take action."
- Use a temporary mitigation if upgrading has to wait. The advisory describes a web application firewall rule and server rewrite rules that block the request patterns used in the attack.
- Check the logs. Atlassian's advisory explains how to search access logs for signs that someone tried to use the flaw.
- Rotate secrets stored in configuration files, such as the Crowd application password, if there is any sign of access. This follows from the watchTowr finding about what those files can contain.
Smaller teams that rely on an IT provider or a hosting partner to run their Atlassian server should ask that provider whether the upgrade has been applied.
What it means if you are choosing a tool
For buyers comparing project management software, this advisory is a reminder of who carries the security work. On a cloud plan, the vendor patches the service for every customer at once. On a self-hosted product, your own team has to spot the advisory, schedule the upgrade and check the logs.
Atlassian is also winding down the self-hosted option for most of these products. Its Data Center end of life page says new customers could no longer buy Data Center subscriptions after 30 March 2026, existing customers can no longer buy new subscriptions or expand licences after 30 March 2028, and subscriptions for the affected products expire on 28 March 2029, when instances become read-only. Atlassian says it will keep shipping "security bug-fixes for critical vulnerabilities" until that date. The page lists Jira Software, Jira Service Management, Confluence and Crowd Data Center as affected, while Bitbucket and Bamboo get a separate hybrid licence option.
So a team still on Jira or Confluence Data Center will get fixes for flaws like this one for now, but it needs a plan for what comes after 2029, whether that is Atlassian Cloud or another tool.
What is still unknown
- Whether attackers are using the flaw. At publication, neither Atlassian nor BleepingComputer reported attacks, but public proof-of-concept code is now available.
- How many self-hosted servers are still unpatched and reachable from the internet. Atlassian has not published a figure.
- Which other sensitive files may be exposed in individual setups. Atlassian says this depends on configuration.
- Whether the flaw has been present for a long time. Atlassian says all versions before the fixed releases are affected but has not said when it was introduced.