Eight Atlassian Products Could Expose Known Files
Atlassian’s 5 October advisory for CVE-2026-21589 affects eight self-managed products. An unauthenticated attacker knowing a file’s exact path and name can read it within the web-application root. Directories cannot be listed. The advisory describes file access, not code execution.
Cloud is patched; Atlassian found no exploitation evidence. Inventory installations; use the fix matrix.
Patch precisely
Until patched, restrict internet access or use the all-product WAF/proxy rule. Tomcat RewriteValve covers only Confluence, Jira Service Management, Jira Software, Bamboo and Crowd. Bitbucket uses urlrewrite.xml; Crucible and Fisheye use the all-product option.


