BlackTree Security · Infrastructure · Automation · AI

Eight Atlassian Products Could Expose Known Files

Atlassian’s 5 October advisory for CVE-2026-21589 affects eight self-managed products. An unauthenticated attacker knowing a file’s exact path and name can read it within the web-application root. Directories cannot be listed. The advisory describes file access, not code execution.

Cloud is patched; Atlassian found no exploitation evidence. Inventory installations; use the fix matrix.

Patch precisely

Until patched, restrict internet access or use the all-product WAF/proxy rule. Tomcat RewriteValve covers only Confluence, Jira Service Management, Jira Software, Bamboo and Crowd. Bitbucket uses urlrewrite.xml; Crucible and Fisheye use the all-product option.

Leave a Reply

Your email address will not be published. Required fields are marked *