Cve 2026 21589 Arbitrary File Access Vulnerability Impacts Multiple Products 1870495748
CVE-2019-13990 - XXE (XML External Entity Injection) Vulnerability In Jira Service Management Data Center and Jira Service Management Server
CVE-2022-1471 - SnakeYAML library RCE Vulnerability impacts Multiple Products
CVE-2023-22522 - RCE Vulnerability In Confluence Data Center and Confluence Server
CVE-2023-22523 - RCE Vulnerability in Assets Discovery
CVE-2023-22524 - RCE Vulnerability in Atlassian Companion App for MacOS
CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server
CVE-2023-22518 - Improper Authorization Vulnerability In Confluence Data Center and Server
CVE-2023-46604 - Apache ActiveMQ RCE Vulnerability impacts Bamboo Data Center and Server
Multiple Products Security Advisory - Git Buffer Overflow - CVE-2022-41903, CVE-2022-23521
Security Bulletin - July 18 2023
Security Bulletin - August 15 2023
Security Bulletin - September 19 2023
Security Bulletin - October 17 2023
Security Bulletin - November 21 2023
Security Bulletin - December 12 2023
Security Bulletin - January 16 2024
Security Bulletin - February 20 2024
Security Bulletin - March 19 2024
Security Bulletin - April 16 2024
Security Bulletin - May 21 2024
Security Bulletin - June 18 2024
Security Bulletin - July 16 2024
Security Bulletin - August 20 2024
Security Bulletin - September 17 2024
Security Bulletin - October 15 2024
Security Bulletin - November 19 2024
Security Bulletin - December 10 2024
Security Bulletin - January 21 2025
Security Bulletin - February 18 2025
Security Bulletin - March 18 2025
Security Bulletin - April 15 2025
Security Bulletin - May 20 2025
Security Bulletin - June 17 2025
Security Bulletin - July 15 2025
Security Bulletin - August 19 2025
Security Bulletin - September 16 2025
Security Bulletin - October 21 2025
Security Bulletin - November 18 2025
Security Bulletin - December 11 2025
Security Bulletin - January 20 2026
Security Bulletin - February 17 2026
Security Bulletin - March 17 2026
Security Bulletin - April 21 2026
Security Bulletin - May 19 2026
Security Bulletin - June 16 2026
Security Bulletin - July 21 2026
CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products
Security Bulletin - August 18 2026
Security Bulletin - September 15 2026
The Atlassian Community is here for you.
CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products
Jira Service Management Data Center
Summary of Vulnerability
All versions of Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye are affected by this vulnerability. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be sensitive files present that increase your risk.
All Data Center products listed below are at risk and require immediate attention. See “What You Need to Do” for detailed instructions.
Affected Atlassian Cloud products have been patched, and our investigation has not found evidence of exploitation. No Cloud customer action is required.
Atlassian rates the severity level of this vulnerability as Critical ( 9.3 with the following vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H ) per our internal assessment. This is our assessment, and you should evaluate its applicability to your own IT environment.
This Arbitrary File Access vulnerability affects all versions prior to the listed fix versions of affected Products. Atlassian recommends patching to the fixed LTS version or later.
Jira Service Management Data Center
All versions are affected
Immediately patch to a fixed version
Atlassian recommends that you patch each of your affected installations to fixed versions or the latest version.
Jira Service Management Data Center
Apply temporary mitigations if unable to patch
Remove your instance from the internet until you can patch or apply mitigations, if possible. Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action.
Option 1: Apply a Web Application Firewall Rule, requires regex filtering (For All Affected Products)
Apply a rule, described below, to your Web Application Firewall or proxy layer. Rule implementation instructions are dependent on your technology (e.g. reverse proxy, AWS WAF, or Cloudflare).
Block any URL containing this regex pattern regex filter (?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).* The intent of this regex is to block .. immediately adjacent to / , \ , or :: .
Block any URL containing this regex pattern
Test that your rule blocks .. immediately adjacent to / , \ , or :: and handles the URL-encoded patterns
Option 2: Block requests using Tomcat’s RewriteValve (For Confluence, JSM, Jira, Bamboo, and Crowd)
First, back up your instance. Then, for each node in your Data Center cluster:
Enable Tomcat’s RewriteValve: Locate the server.xml file: On Confluence, JSM, Jira, and Bamboo: conf/server.xml On Crowd: either apache-tomcat/conf/Catalina/localhost/crowd.xml or apache-tomcat/conf/server.xml , whichever has your application (see below) Make a copy of this file as a backup Inside this file identify the element representing the application, the docBase attribute will be a path including the product name; in the standard setup this will be the only element Add the following line within that element if it is not already there:
Enable Tomcat’s RewriteValve:
Locate the server.xml file: On Confluence, JSM, Jira, and Bamboo: conf/server.xml On Crowd: either apache-tomcat/conf/Catalina/localhost/crowd.xml or apache-tomcat/conf/server.xml , whichever has your application (see below)
Locate the server.xml file:
On Confluence, JSM, Jira, and Bamboo: conf/server.xml
On Crowd: either apache-tomcat/conf/Catalina/localhost/crowd.xml or apache-tomcat/conf/server.xml , whichever has your application (see below)
Make a copy of this file as a backup
Make a copy of this file as a backup
Inside this file identify the element representing the application, the docBase attribute will be a path including the product name; in the standard setup this will be the only element
Add the following line within that element if it is not already there:
Add the following line within that element if it is not already there:
Install the configuration: Locate the WEB-INF directory: On Confluence: confluence/WEB-INF On JSM/Jira: atlassian-jira/WEB-INF On Bamboo: bamboo/WEB-INF or atlassian-bamboo/WEB-INF On Crowd: crowd-webapp/WEB-INF Within this directory, check if the file rewrite.config exists If it exists: Make a copy of the existing rewrite.config file as a backup Append the existing file with the rewrite.config code block provided below If it does not exist: Create a rewrite.config file in the directory with the code block provided below
Install the configuration:
Locate the WEB-INF directory: On Confluence: confluence/WEB-INF On JSM/Jira: atlassian-jira/WEB-INF On Bamboo: bamboo/WEB-INF or atlassian-bamboo/WEB-INF On Crowd: crowd-webapp/WEB-INF
On Confluence: confluence/WEB-INF
On JSM/Jira: atlassian-jira/WEB-INF
On Bamboo: bamboo/WEB-INF or atlassian-bamboo/WEB-INF
On Crowd: crowd-webapp/WEB-INF
Within this directory, check if the file rewrite.config exists
Within this directory, check if the file rewrite.config exists
If it exists: Make a copy of the existing rewrite.config file as a backup Append the existing file with the rewrite.config code block provided below
Make a copy of the existing rewrite.config file as a backup
Make a copy of the existing rewrite.config file as a backup
Append the existing file with the rewrite.config code block provided below
Append the existing file with the rewrite.config code block provided below
If it does not exist: Create a rewrite.config file in the directory with the code block provided below
If it does not exist:
Create a rewrite.config file in the directory with the code block provided below
Create a rewrite.config file in the directory with the code block provided below
Option 3: Add rule to urlrewrite.xml (For Bitbucket only)
First, back up your instance.
For a clustered system, this patch should be applied to all nodes. Similarly, apply the patch to all Bitbucket mirrors and Bitbucket mirror farm nodes. Edit the /app/WEB-INF/urlrewrite.xml file Add a new to the top of the file, before other s (?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).* 404 /mvc/error404 When the mitigation is applied, the top of the urlrewrite.xml file should look like the below: (?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).* 404 /mvc/error404 [...] Restart Bitbucket Data Center
Edit the /app/WEB-INF/urlrewrite.xml file
Add a new to the top of the file, before other s (?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).* 404 /mvc/error404 When the mitigation is applied, the top of the urlrewrite.xml file should look like the below: (?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).* 404 /mvc/error404 [...]
When the mitigation is applied, the top of the urlrewrite.xml file should look like the below:
Restart Bitbucket Data Center
Atlassian cannot confirm if your instances have been affected by this vulnerability. You should engage your local security team to check all affected instances for evidence of compromise.
Paths for investigating evidence of compromise in your access logs:
URL-decode each access-log request line (up to two decoding passes) before searching, then check for .. immediately adjacent to / , \ , or :: ; or
URL-decode each access-log request line (up to two decoding passes) before searching, then check for .. immediately adjacent to / , \ , or :: ; or
raw (non-decoded) log lines directly using the regex above
raw (non-decoded) log lines directly using the regex above
For a full description of the latest versions, see the release notes for your product below.
Jira Service Management Data Center
Jira Service Management Data Center
You can download the latest version for your product from the download center:
Jira Service Management Data Center
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
