Skip to content
Critical Path Traversal Vulnerability in Atlassian Data Center Products

Critical Path Traversal Vulnerability in Atlassian Data Center Products

First seen 6 Oct 2026, 10:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 11:27 UTC
  • •CVE-2026-21589 affects eight Atlassian Data Center products.
  • •The vulnerability allows unauthenticated file access if the filename and path are known.
  • •Immediate patching is recommended to prevent potential data breaches.

On October 5, 2026, Atlassian disclosed CVE-2026-21589, a critical path traversal vulnerability with a CVSS score of 9.3, affecting eight self-hosted Data Center products including Jira, Confluence, and Bitbucket. This flaw allows unauthenticated attackers to read specific files from the web application root directory if they know the exact filename and path. While no remote code execution is possible, the risk of unauthorized data access is significant. Atlassian's cloud products have been patched, and there is no evidence of active exploitation. Organizations are urged to upgrade to specified fixed versions to mitigate the risk. Temporary mitigations include implementing web application firewall rules. The CVE documentation contains discrepancies regarding fixed versions, complicating risk assessment for administrators.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2021-08-16
CVE-2021-26086 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-17
CVE-2026-19478 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-05
CVE-2026-21589 disclosed
Atlassian announced a critical path traversal vulnerability affecting multiple Data Center products.
Forkast.News
2026-10-06
Patch versions released
Atlassian provided fixed versions for all affected Data Center products to address the vulnerability.
Thehackernews

More articles in this cluster (7)

Following this threat?

Track Atlassian and CVE-2021-26086 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which Atlassian products are affected?
The vulnerability impacts Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye.
What should I do if I can't patch immediately?
Atlassian recommends implementing temporary mitigations such as WAF rules to block double-dot traversal patterns.
Is there any evidence of exploitation?
Atlassian has not found any evidence of exploitation for this vulnerability in the wild.