Atlassian has issued an urgent security advisory for its datacenter products, warning of a critical arbitrary file access vulnerability tracked as CVE-2026-21589. The flaw, rated 9.3 out of 10, affects the datacenter editions of Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye. An unauthenticated attacker could exploit it to read specific files inside the web application root directory.
According to The Register, the company cautioned that some configurations may contain sensitive files that increase risk. The attack is not trivial: the attacker must know the exact filename and path, and the vulnerability does not allow directory listing. Still, Atlassian is telling users to patch promptly.
Atlassian has already released updated versions of the affected products, so administrators need to schedule an upgrade. For those who cannot patch immediately, the company advises restricting external network access, including instances that require user authentication. Users on Atlassian's cloud platform do not need to take action, as the flaws have been fixed in its SaaS offerings.