Skip to content

CVE-2026-21589

Confluence.Atlassian • October 6, 2026

CVE-2019-13990 - XXE (XML External Entity Injection) Vulnerability In Jira Service Management Data Center and Jira Service Management Server

CVE-2022-1471 - SnakeYAML library RCE Vulnerability impacts Multiple Products

CVE-2023-22522 - RCE Vulnerability In Confluence Data Center and Confluence Server

CVE-2023-22523 - RCE Vulnerability in Assets Discovery

CVE-2023-22524 - RCE Vulnerability in Atlassian Companion App for MacOS

CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server

CVE-2023-22518 - Improper Authorization Vulnerability In Confluence Data Center and Server

CVE-2023-46604 - Apache ActiveMQ RCE Vulnerability impacts Bamboo Data Center and Server

Multiple Products Security Advisory - Git Buffer Overflow - CVE-2022-41903, CVE-2022-23521

Security Bulletin - July 18 2023

Security Bulletin - August 15 2023

Security Bulletin - September 19 2023

Security Bulletin - October 17 2023

Security Bulletin - November 21 2023

Security Bulletin - December 12 2023

Security Bulletin - January 16 2024

Security Bulletin - February 20 2024

Security Bulletin - March 19 2024

Security Bulletin - April 16 2024

Security Bulletin - May 21 2024

Security Bulletin - June 18 2024

Security Bulletin - July 16 2024

Security Bulletin - August 20 2024

Security Bulletin - September 17 2024

Security Bulletin - October 15 2024

Security Bulletin - November 19 2024

Security Bulletin - December 10 2024

Security Bulletin - January 21 2025

Security Bulletin - February 18 2025

Security Bulletin - March 18 2025

Security Bulletin - April 15 2025

Security Bulletin - May 20 2025

Security Bulletin - June 17 2025

Security Bulletin - July 15 2025

Security Bulletin - August 19 2025

Security Bulletin - September 16 2025

Security Bulletin - October 21 2025

Security Bulletin - November 18 2025

Security Bulletin - December 11 2025

Security Bulletin - January 20 2026

Security Bulletin - February 17 2026

Security Bulletin - March 17 2026

Security Bulletin - April 21 2026

Security Bulletin - May 19 2026

Security Bulletin - June 16 2026

Security Bulletin - July 21 2026

CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products

Security Bulletin - August 18 2026

Security Bulletin - September 15 2026

The Atlassian Community is here for you.

CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products

Bitbucket Data Center

Confluence Data Center

Jira Service Management Data Center

Jira Software Data Center

Summary of Vulnerability

All versions of Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye are affected by this vulnerability. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be sensitive files present that increase your risk.

All Data Center products listed below are at risk and require immediate attention. See “What You Need to Do” for detailed instructions.

Affected Atlassian Cloud products have been patched, and our investigation has not found evidence of exploitation. No Cloud customer action is required.

Atlassian rates the severity level of this vulnerability as Critical ( 9.3 with the following vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H ) per our internal assessment. This is our assessment, and you should evaluate its applicability to your own IT environment.

This Arbitrary File Access vulnerability affects all versions prior to the listed fix versions of affected Products. Atlassian recommends patching to the fixed LTS version or later.

Bitbucket Data Center

Confluence Data Center

Jira Service Management Data Center

Jira Software Data Center

All versions are affected

Immediately patch to a fixed version

Atlassian recommends that you patch each of your affected installations to fixed versions or the latest version.

Jira Service Management Data Center

Jira Software Data Center

Apply temporary mitigations if unable to patch

Remove your instance from the internet until you can patch or apply mitigations, if possible. Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action.

Option 1: Apply a Web Application Firewall Rule, requires regex filtering (For All Affected Products)

Apply a rule, described below, to your Web Application Firewall or proxy layer. Rule implementation instructions are dependent on your technology (e.g. reverse proxy, AWS WAF, or Cloudflare).

Block any URL containing this regex pattern regex filter (?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).* The intent of this regex is to block .. immediately adjacent to / , \ , or :: .

Block any URL containing this regex pattern

Test that your rule blocks .. immediately adjacent to / , \ , or :: and handles the URL-encoded patterns

Option 2: Block requests using Tomcat’s RewriteValve (For Confluence, JSM, Jira, Bamboo, and Crowd)

First, back up your instance. Then, for each node in your Data Center cluster:

Enable Tomcat’s RewriteValve: Locate the server.xml file: On Confluence, JSM, Jira, and Bamboo: conf/server.xml On Crowd: either apache-tomcat/conf/Catalina/localhost/crowd.xml or apache-tomcat/conf/server.xml , whichever has your application (see below) Make a copy of this file as a backup Inside this file identify the element representing the application, the docBase attribute will be a path including the product name; in the standard setup this will be the only element Add the following line within that element if it is not already there:

Enable Tomcat’s RewriteValve:

Locate the server.xml file: On Confluence, JSM, Jira, and Bamboo: conf/server.xml On Crowd: either apache-tomcat/conf/Catalina/localhost/crowd.xml or apache-tomcat/conf/server.xml , whichever has your application (see below)

Locate the server.xml file:

On Confluence, JSM, Jira, and Bamboo: conf/server.xml

On Crowd: either apache-tomcat/conf/Catalina/localhost/crowd.xml or apache-tomcat/conf/server.xml , whichever has your application (see below)

Make a copy of this file as a backup

Make a copy of this file as a backup

Inside this file identify the element representing the application, the docBase attribute will be a path including the product name; in the standard setup this will be the only element

Add the following line within that element if it is not already there:

Add the following line within that element if it is not already there:

Install the configuration: Locate the WEB-INF directory: On Confluence: confluence/WEB-INF On JSM/Jira: atlassian-jira/WEB-INF On Bamboo: bamboo/WEB-INF or atlassian-bamboo/WEB-INF On Crowd: crowd-webapp/WEB-INF Within this directory, check if the file rewrite.config exists If it exists: Make a copy of the existing rewrite.config file as a backup Append the existing file with the rewrite.config code block provided below If it does not exist: Create a rewrite.config file in the directory with the code block provided below

Install the configuration:

Locate the WEB-INF directory: On Confluence: confluence/WEB-INF On JSM/Jira: atlassian-jira/WEB-INF On Bamboo: bamboo/WEB-INF or atlassian-bamboo/WEB-INF On Crowd: crowd-webapp/WEB-INF

On Confluence: confluence/WEB-INF

On JSM/Jira: atlassian-jira/WEB-INF

On Bamboo: bamboo/WEB-INF or atlassian-bamboo/WEB-INF

On Crowd: crowd-webapp/WEB-INF

Within this directory, check if the file rewrite.config exists

Within this directory, check if the file rewrite.config exists

If it exists: Make a copy of the existing rewrite.config file as a backup Append the existing file with the rewrite.config code block provided below

Make a copy of the existing rewrite.config file as a backup

Make a copy of the existing rewrite.config file as a backup

Append the existing file with the rewrite.config code block provided below

Append the existing file with the rewrite.config code block provided below

If it does not exist: Create a rewrite.config file in the directory with the code block provided below

If it does not exist:

Create a rewrite.config file in the directory with the code block provided below

Create a rewrite.config file in the directory with the code block provided below

Option 3: Add rule to urlrewrite.xml (For Bitbucket only)

First, back up your instance.

For a clustered system, this patch should be applied to all nodes. Similarly, apply the patch to all Bitbucket mirrors and Bitbucket mirror farm nodes. Edit the /app/WEB-INF/urlrewrite.xml file Add a new to the top of the file, before other s (?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).* 404 /mvc/error404 When the mitigation is applied, the top of the urlrewrite.xml file should look like the below: (?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).* 404 /mvc/error404 [...] Restart Bitbucket Data Center

Edit the /app/WEB-INF/urlrewrite.xml file

Add a new to the top of the file, before other s (?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).* 404 /mvc/error404 When the mitigation is applied, the top of the urlrewrite.xml file should look like the below: (?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).* 404 /mvc/error404 [...]

When the mitigation is applied, the top of the urlrewrite.xml file should look like the below:

Restart Bitbucket Data Center

Atlassian cannot confirm if your instances have been affected by this vulnerability. You should engage your local security team to check all affected instances for evidence of compromise.

Paths for investigating evidence of compromise in your access logs:

URL-decode each access-log request line (up to two decoding passes) before searching, then check for .. immediately adjacent to / , \ , or :: ; or

URL-decode each access-log request line (up to two decoding passes) before searching, then check for .. immediately adjacent to / , \ , or :: ; or

raw (non-decoded) log lines directly using the regex above

raw (non-decoded) log lines directly using the regex above

For a full description of the latest versions, see the release notes for your product below.

Bitbucket Data Center

Bitbucket Data Center

Confluence Data Center

Confluence Data Center

Jira Service Management Data Center

Jira Service Management Data Center

Jira Software Data Center

Jira Software Data Center

You can download the latest version for your product from the download center:

Bitbucket Data Center

Bitbucket Data Center

Confluence Data Center

Confluence Data Center

Jira Service Management Data Center

Jira Service Management Data Center

Jira Software Data Center

Jira Software Data Center