Cyber Security News

Atlassian CVE-2026-21589 Flaw Exposes Files in Jira and Confluence Data Center

Atlassian has announced a critical vulnerability related to arbitrary file access that affects Jira Software Data Center and Confluence Data Center.

This vulnerability, tracked as CVE-2026-21589, has a CVSS score of 9.3 and allows unauthenticated attackers to access specific files within the web root directories of the affected applications without needing valid credentials or accounts.

Atlassian CVE-2026-21589 Flaw

According to Atlassian advisories, exploiting this vulnerability requires attackers to know the exact filename and path of the targeted resource.

The vulnerability does not facilitate directory enumeration or listing, which limits attackers’ ability to discover files directly. However, installations with sensitive files in accessible application directories face increased exposure risk.

In the Confluence advisory, the issue is categorized under path traversal, with an “Arbitrary Read/Write” classification. Nevertheless, the published description highlights unauthenticated file access and does not indicate the ability to modify files or execute code.

Administrators should distinguish between the documented impact and broader vulnerability descriptions when assessing potential consequences for their systems.

Atlassian indicates that all versions before the applicable fixes are affected. Fixes for Jira Data Center are available in versions 9.12.40, 10.3.26, and 11.3.12, while Confluence Data Center fixes can be found in versions 9.2.26 and 10.2.19.

Organizations using older, unsupported releases should upgrade to a patched long-term support release or a later version.

For Atlassian Cloud products, Atlassian has already implemented patches and says its investigation found no evidence of exploitation. Cloud customers do not need to take action.

However, this statement should not be seen as confirmation that every customer-managed Data Center deployment is free from compromise, especially where vulnerable instances are still publicly accessible.

For administrators who cannot patch immediately, Atlassian recommends removing affected instances from the internet whenever possible.

Restrict external network access, even for applications that require user authentication, because exploitation does not require a login.

These containment measures will help reduce exposure while organizations prepare for upgrades or implement the vendor’s temporary mitigations.

One mitigation strategy is to use a web application firewall or a reverse proxy rule to block suspicious traversal patterns. Atlassian provides a regular expression to detect double dots immediately adjacent to forward slashes, backslashes, or double colons.

This expression also accounts for encoded variants, and administrators must test the filtering against the specified URL-encoded patterns before deployment.

Another mitigation uses Apache Tomcat’s RewriteValve. Administrators should back up each instance, shut down each cluster node, and enable the valve in the application’s Context element within conf/server.xml.

They must then install or append Atlassian’s supplied rewrite.config to atlassian-jira/WEB-INF for Jira or confluence/WEB-INF for Confluence before safely restarting the node.

Atlassian explicitly warns that these mitigations are limited and cannot substitute for patching. Security teams should prioritize securing internet-facing deployments, ensure that every cluster node receives the required changes, and schedule upgrades to the applicable fixed release as soon as possible.

The immediate goal is to prevent unauthenticated access to potentially sensitive application files across deployments.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

3 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago