Security5 publishers3 min readPublished
Atlassian tells Data Center customers to pull exposed servers offline over a 9.3 file-read flaw
Atlassian disclosed a 9.3-rated flaw, CVE-2026-21589, that lets attackers with no login read known files in 8 self-hosted Data Center products. It wants internet-facing instances taken offline or cut off from outside access until they are upgraded or behind a blocking rule.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- An attacker must already know a file's exact name and path and cannot list what the web application root directory holds.
- Atlassian has already patched its affected cloud products, and cloud customers do not need to take any action.
- Atlassian's three temporary blocking rules all reject URLs containing .. next to a slash, a backslash or ::, including URL-encoded forms.
- Atlassian's CVE record gives different fix versions from its advisory tickets for two products, Crowd and Bamboo.
- The CVE record also marks every version of Bamboo, Bitbucket, Confluence and Crowd Server as affected, with no fixed version listed for any of them.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- cost Holding off on the upgrade does not avoid downtime on most products: the in-application stopgap needs every node restarted on 6 of 8, and only the edge WAF or proxy rule leaves nodes untouched.
- contradiction A version scan keyed to the CVE record can pass Crowd and Bamboo hosts that Atlassian's own tickets still count as vulnerable.
- exposure Shops still running the four affected Server editions have no build to upgrade to, leaving them with blocking rules or cutting outside access.
- constraint A team that finds traversal hits in its logs cannot tell from Atlassian's method which requests returned a file, so it has to assume the matching files were read.
Anyone who can reach an affected instance over the network can attempt this, because no account is needed [1]. Atlassian's CVE record classes it as a path traversal, where a request uses a specially built file path to reach files it should not [3]. How much an attacker gets depends on what sits in the web application root, the folder that holds the application itself. Atlassian says that folder may contain sensitive files in some configurations [11].
For exposed hosts, the emergency-patch reading holds. Atlassian's restriction advice covers any instance reachable from the public internet, including one that requires a login, and it runs until the host is upgraded or a blocking rule is in place [5]. The affected range is every version before each product's fix and may include end-of-life releases. Atlassian recommends moving to a fixed long-term support version or later [16].
The stopgaps carry their own downtime. The Tomcat RewriteValve rule for Confluence, Jira Software, Jira Service Management, Bamboo and Crowd goes on each node, and each node must be shut down and restarted. Bitbucket's urlrewrite.xml change goes on every node, mirror and mirror farm node, followed by a restart [7]. Six of the 8 products therefore need restarts to take an in-application rule [21]. Crucible and Fisheye can only use the rule on a web application firewall or reverse proxy [8]. Atlassian says the mitigations "are limited and not a replacement for patching your instance" [24].
Version checks need care. For Crowd, the CVE record lists 7.1.1, a release Atlassian's notes date to November 27, 2025, more than 10 months before disclosure [18]. Atlassian's Crowd ticket gives 7.1.7 in its fix version field, while a table in the same ticket shows 7.1.6, a version the ticket also lists as affected [17]. For Bamboo, one field in the record says 10.2.4 and its description says 10.2.24 [19].
Server customers have fewer options. Crowd has had no Server release since 5.2 in September 2023, so none of the fixed Crowd versions are Server builds [23]. For Jira Software Server the record lists 9.12.40 and later as unaffected, for Jira Service Management Server 5.12.40, and for Crucible and Fisheye Server 4.9.15 [22].
Atlassian says its investigation has not found evidence of exploitation [10]. On self-hosted instances it goes no further. "Atlassian cannot confirm if your instances have been affected by this vulnerability," the advisory says [12]. The log hunt it describes is to URL-decode each request line up to two times and look for the same .. patterns, or to run the block pattern over raw log lines [13]. The advisory does not explain how to tell a failed attempt from a request that returned a file [14].
This class of bug has been exploited in Atlassian software before. CVE-2021-26086 was a path traversal in Jira [25]. For CVE-2026-21589, the public record so far is a disclosure on October 5 and a list of fixed versions dated October 6 [2][15].
What to watch
- Atlassian correcting the Crowd and Bamboo fix versions in the CVE record, or resolving the 7.1.6 versus 7.1.7 conflict inside its own Crowd ticket.
- Any report of attacks on self-hosted Data Center or Server instances, beyond Atlassian's statement that it cannot confirm whether customer instances were hit.
- Whether Atlassian ships fixes for Bamboo, Bitbucket, Confluence and Crowd Server, or says whether Server licenses can run Jira Software Server 9.12.40 and the other listed unaffected builds.