Atlassian patches critical flaw in eight self-hosted products
Atlassian has disclosed and patched a critical vulnerability that could let unauthenticated attackers read specific files from the web application roots of eight self-hosted Data Center products. The company rated the flaw, tracked as CVE-2026-21589, 9.3 out of 10 under CVSS 4.0 and urged customers to upgrade affected installations or restrict their external access while applying temporary safeguards. The affected products are Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. Atlassian’s advisory says all versions before the product-specific fixed releases are affected. The flaw does not require a login, but an attacker must know the exact name and path of a target file. It does not allow directory contents to be listed. Atlassian warned that some configurations may store sensitive files in the affected locations, potentially increasing the risk. The company described the 9.3 score as its own assessment and advised customers to evaluate how the issue applies to their systems.