Close Menu
NCIJ Network NCIJ Network
    What's Hot

    What Our Reporter Learned From Gambling on DraftKings for 10 Weeks — ProPublica

    October 6, 2026

    Israel warns Gazans will pay ‘heavy price’ for any October 7 attacks on military

    October 6, 2026

    Der erste Machtbeweis der AfD in Magdeburg – POLITICO

    October 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • What Our Reporter Learned From Gambling on DraftKings for 10 Weeks — ProPublica
    • Israel warns Gazans will pay ‘heavy price’ for any October 7 attacks on military
    • Der erste Machtbeweis der AfD in Magdeburg – POLITICO
    • Loss of green space could be issue that decides Holborn and St Pancras byelection | Holborn and St Pancras byelection
    • Democrats Eyeing the House Face a Conundrum: Rent or Buy?
    • Interview with Ansa
    • After Factory’s public spat with Khosla, Menlo proudly invests
    • Engineer sentenced for locking over 3,000 devices on employer network
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, October 6
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 6, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product’s web application root directory.

    The attacker must already know a file’s exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and listed a fixed version for each product.

    The web application root directory is the folder on the server that holds the web application itself. In some configurations, it may contain sensitive files, which raises the risk, according to Atlassian.

    Atlassian’s cloud products affected by the flaw have already been patched, and cloud customers do not need to take any action.

    Atlassian advises customers who cannot upgrade all at once to take the instance offline if possible. Any instance reachable from the public internet, including one that requires a login, should be restricted from outside network access until it is upgraded or a temporary blocking rule is in place.

    Affected Products and Fixed Versions

    The flaw affects all versions of the 8 products before the fixed versions listed below. That may include versions that have reached end of life, according to Atlassian, which recommends upgrading to a fixed long-term support (LTS) version or later.

    Atlassian listed these fixed versions as of October 6:

    Product Fixed versions

    Bitbucket Data Center
    9.4.26, 10.2.8, 10.5.1

    Confluence Data Center
    9.2.26, 10.2.19

    Jira Software Data Center
    9.12.40, 10.3.26, 11.3.12

    Jira Service Management Data Center
    5.12.40, 10.3.26, 11.3.12

    Bamboo Data Center
    10.2.24, 12.1.12

    Crowd Data Center
    6.3.7, 7.0.3, 7.1.7, 7.2.4

    Crucible
    4.9.15

    Fisheye
    4.9.15

    For Crowd’s 7.1 branch, the ticket’s fix version field said 7.1.7. A table in the same ticket showed 7.1.6, which the ticket also listed as an affected version.

    The CVE record Atlassian filed gave different numbers for 2 products. For Crowd, it listed 7.1.1, which the Crowd 7.1 release notes date to November 27, 2025, more than 10 months before the flaw was disclosed. For Bamboo, one field said 10.2.4, while the record’s own description said 10.2.24.

    Cybersecurity

    The CVE record also listed the Server editions of these products, Atlassian’s older self-hosted line, which the advisory did not mention. It marked every version of Bamboo Server, Bitbucket Server, Confluence Server, and Crowd Server as affected and listed no fixed versions for them.

    For Jira Software Server, the record listed versions from 9.12.40 as unaffected, for Jira Service Management Server from 5.12.40, and for Crucible Server and Fisheye Server from 4.9.15. It did not say whether Server licenses can run those versions.

    Crowd has had no Server release since version 5.2 in September 2023, according to Atlassian’s Crowd release notes, so none of the fixed Crowd versions are Server releases.

    If You Cannot Upgrade Yet

    Atlassian labels the flaw a path traversal in the CVE record. In a path traversal, a request uses a specially built file path to reach files it should not.

    Atlassian describes 3 temporary blocking rules, which it calls mitigations. All 3 block requests whose URL contains .. directly next to /, or ::, including URL-encoded forms.

    Which ones apply depends on the product:

    • All 8 products: a rule on a web application firewall (WAF) or reverse proxy that blocks matching URLs.
    • Confluence, Jira Software, Jira Service Management, Bamboo and Crowd: a Tomcat RewriteValve rule, installed on each node, which must be shut down and restarted.
    • Bitbucket: a rule in urlrewrite.xml, applied to every node, mirror and mirror farm node, followed by a restart.

    Crucible and Fisheye have only the first option. The advisory gives the rule and the file changes for each one.

    The mitigations “are limited and not a replacement for patching your instance,” Atlassian says in its product tickets.

    Checking for Past Access

    Atlassian said its affected cloud products have been patched and that its investigation has not found evidence of exploitation. Bitbucket Cloud is not affected.

    The advisory does not say whether attacks on self-hosted instances have been seen. “Atlassian cannot confirm if your instances have been affected by this vulnerability,” it says.

    It tells customers to have their security teams search access logs. One method is to URL-decode each request line, up to 2 times, and look for .. directly next to /, or ::. The other is to run Atlassian’s block pattern over the raw log lines.

    Cybersecurity

    The advisory does not explain how to distinguish a failed attempt from a request that returned a file, or what else a customer who encounters such requests should do after upgrading.

    Attackers have exploited this kind of flaw in an Atlassian product before. CVE-2021-26086 is a path traversal vulnerability in Jira Server and Data Center that allows remote attackers to read specific files. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its catalog of known exploited vulnerabilities on November 12, 2024.

    How Atlassian Scored the Flaw

    The 9.3 rating uses version 4.0 of the Common Vulnerability Scoring System (CVSS) and is Atlassian’s own. The company tells customers to judge how it applies to their environment.

    The score rates the flaw as reachable over the network without privileges or user action. It rates the effect on the vulnerable system’s confidentiality as high, its integrity and availability as none, and on other systems as high.

    The advisory does not identify the sensitive files or the configurations that contain them, nor does it explain the high rating for other systems.

    Atlassian Attackers critical Files Flaw lets products Read unauthenticated
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Engineer sentenced for locking over 3,000 devices on employer network

    ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

    Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

    Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

    South Korea probes bank breaches amid suspected AI-powered attacks

    New Dell System Update flaw lets hackers gain root privileges

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    What Our Reporter Learned From Gambling on DraftKings for 10 Weeks — ProPublica

    October 6, 2026

    Israel warns Gazans will pay ‘heavy price’ for any October 7 attacks on military

    October 6, 2026

    Der erste Machtbeweis der AfD in Magdeburg – POLITICO

    October 6, 2026

    Loss of green space could be issue that decides Holborn and St Pancras byelection | Holborn and St Pancras byelection

    October 6, 2026
    Latest Posts

    What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience

    August 9, 2026

    Britain is paying the price for failing to invest in its young people | Richard Partington

    August 9, 2026

    A Democratic Socialist Spreads the Word, Even in Hostile Territory

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    What Our Reporter Learned From Gambling on DraftKings for 10 Weeks — ProPublica

    October 6, 2026

    Israel warns Gazans will pay ‘heavy price’ for any October 7 attacks on military

    October 6, 2026

    Der erste Machtbeweis der AfD in Magdeburg – POLITICO

    October 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.