Atlassian warns of critical file access flaw in its datacenter products
Tells users ‘action required’ – but maybe don’t make that action a Jira ticket, because it has this bug
Atlassian has cautioned its users to promptly apply patches to its datacenter products to thwart potential attackers who could gain access to their files. The company notified users via email on Monday, directing them to a security bulletin detailing CVE-2026-21589. This critical arbitrary file access vulnerability, rated 9.3, affects the datacenter versions of several Atlassian products, including Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye.
The flaw allows an unauthenticated attacker to access specific files within the web application root directory in affected versions, posing a significant risk as sensitive files could potentially be compromised. However, attackers would need to know the exact filename and path to exploit the vulnerability, and the issue does not enable unauthorized users to view directory contents.
Atlassian has updated its products, but users only need to upgrade to a safe version. Those unable to patch immediately should isolate their instances from the internet if possible. The advisory also outlines mitigations and guidance on identifying if instances require the fix. Users who migrated from datacenter products to Atlassian's cloud-based SaaS do not need to take any action, as the vulnerabilities have already been addressed in the cloud version.
This outcome supports Atlassian's strategic shift towards cloud-based services, initiated in 2020 and further refined in 2023, when the company discontinued its datacenter software and reduced its workforce by ten percent. Despite initial challenges, including an unsuccessful lift-and-shift tool, Atlassian’s share price has tripled since March 2026, indicating investor confidence in the company's AI-driven workflow strategy.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.