A crucial flaw in 8 Atlassian Knowledge Heart merchandise, which prospects host themselves, permits an attacker with no login entry to learn particular information in every product’s net software root listing.
The attacker should already know a file’s precise title and path and can’t record what the listing holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and listed a hard and fast model for every product.
The net software root listing is the folder on the server that holds the net software itself. In some configurations, it might include delicate information, which raises the danger, in accordance with Atlassian.
Atlassian’s cloud merchandise affected by the flaw have already been patched, and cloud prospects don’t have to take any motion.
Atlassian advises prospects who can not improve abruptly to take the occasion offline if doable. Any occasion reachable from the general public web, together with one which requires a login, ought to be restricted from exterior community entry till it’s upgraded or a short lived blocking rule is in place.
Affected Merchandise and Fastened Variations
The flaw impacts all variations of the 8 merchandise earlier than the mounted variations listed beneath. Which will embody variations which have reached finish of life, in accordance with Atlassian, which recommends upgrading to a hard and fast long-term help (LTS) model or later.
Atlassian listed these mounted variations as of October 6:
| Product | Fastened variations |
|---|---|
|
Bitbucket Knowledge Heart |
9.4.26, 10.2.8, 10.5.1 |
|
Confluence Knowledge Heart |
9.2.26, 10.2.19 |
|
Jira Software program Knowledge Heart |
9.12.40, 10.3.26, 11.3.12 |
|
Jira Service Administration Knowledge Heart |
5.12.40, 10.3.26, 11.3.12 |
|
Bamboo Knowledge Heart |
10.2.24, 12.1.12 |
|
Crowd Knowledge Heart |
6.3.7, 7.0.3, 7.1.7, 7.2.4 |
|
Crucible |
4.9.15 |
|
Fisheye |
4.9.15 |
For Crowd’s 7.1 department, the ticket’s repair model area stated 7.1.7. A desk in the identical ticket confirmed 7.1.6, which the ticket additionally listed as an affected model.
The CVE file Atlassian filed gave totally different numbers for two merchandise. For Crowd, it listed 7.1.1, which the Crowd 7.1 launch notes date to November 27, 2025, greater than 10 months earlier than the flaw was disclosed. For Bamboo, one area stated 10.2.4, whereas the file’s personal description stated 10.2.24.
The CVE file additionally listed the Server editions of those merchandise, Atlassian’s older self-hosted line, which the advisory didn’t point out. It marked each model of Bamboo Server, Bitbucket Server, Confluence Server, and Crowd Server as affected and listed no mounted variations for them.
For Jira Software program Server, the file listed variations from 9.12.40 as unaffected, for Jira Service Administration Server from 5.12.40, and for Crucible Server and Fisheye Server from 4.9.15. It didn’t say whether or not Server licenses can run these variations.
Crowd has had no Server launch since model 5.2 in September 2023, in accordance with Atlassian’s Crowd launch notes, so not one of the mounted Crowd variations are Server releases.
If You Can’t Improve But
Atlassian labels the flaw a path traversal within the CVE file. In a path traversal, a request makes use of a specifically constructed file path to achieve information it mustn’t.
Atlassian describes 3 non permanent blocking guidelines, which it calls mitigations. All 3 block requests whose URL accommodates .. immediately subsequent to /, or ::, together with URL-encoded kinds.
Which of them apply will depend on the product:
- All 8 merchandise: a rule on an internet software firewall (WAF) or reverse proxy that blocks matching URLs.
- Confluence, Jira Software program, Jira Service Administration, Bamboo and Crowd: a Tomcat RewriteValve rule, put in on every node, which should be shut down and restarted.
- Bitbucket: a rule in urlrewrite.xml, utilized to each node, mirror and mirror farm node, adopted by a restart.
Crucible and Fisheye have solely the primary possibility. The advisory offers the rule and the file modifications for every one.
The mitigations “are restricted and never a substitute for patching your occasion,” Atlassian says in its product tickets.
Checking for Previous Entry
Atlassian stated its affected cloud merchandise have been patched and that its investigation has not discovered proof of exploitation. Bitbucket Cloud will not be affected.
The advisory doesn’t say whether or not assaults on self-hosted situations have been seen. “Atlassian can not affirm in case your situations have been affected by this vulnerability,” it says.
It tells prospects to have their safety groups search entry logs. One methodology is to URL-decode every request line, as much as 2 instances, and search for .. immediately subsequent to /, or ::. The opposite is to run Atlassian’s block sample over the uncooked log traces.
The advisory doesn’t clarify the way to distinguish a failed try from a request that returned a file, or what else a buyer who encounters such requests ought to do after upgrading.
Attackers have exploited this type of flaw in an Atlassian product earlier than. CVE-2021-26086 is a path traversal vulnerability in Jira Server and Knowledge Heart that enables distant attackers to learn particular information. The U.S. Cybersecurity and Infrastructure Safety Company (CISA) added it to its catalog of recognized exploited vulnerabilities on November 12, 2024.
How Atlassian Scored the Flaw
The 9.3 score makes use of model 4.0 of the Widespread Vulnerability Scoring System (CVSS) and is Atlassian’s personal. The corporate tells prospects to evaluate the way it applies to their setting.
The rating charges the flaw as reachable over the community with out privileges or consumer motion. It charges the impact on the susceptible system’s confidentiality as excessive, its integrity and availability as none, and on different techniques as excessive.
The advisory doesn’t establish the delicate information or the configurations that include them, nor does it clarify the excessive score for different techniques.










