Path traversal in Jira Software Data Center - CVE-2026-21589
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to read files within the web application root directory.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in Jira Data Center when handling requests containing path traversal sequences. A remote attacker can send a specially crafted request to read files within the web application root directory.
Exploitation requires prior knowledge of the target file's exact name and path, and directory contents cannot be enumerated.
Affected software
Fisheye
Crucible Data Center
Jira Service Management Data Center
Crowd Data Center
Confluence Data Center
Bitbucket Data Center
Bamboo Data Center
Crowd Server
How to mitigate CVE-2026-21589
Fisheye - update to 4.9.15
Crucible Data Center - update to 4.9.15
Jira Service Management Data Center - addressed in versions 5.12.40, 10.3.26, 11.3.12
Crowd Data Center - addressed in versions 6.3.7, 7.0.3, 7.1.7, 7.2.4
Crowd Server - addressed in versions 6.3.7, 7.0.3, 7.1.7, 7.2.4
Confluence Data Center - addressed in versions 9.2.26, 10.2.19
Bitbucket Data Center - addressed in versions 9.4.26, 10.2.8, 10.5.1
Bamboo Data Center - addressed in versions 10.2.24, 12.1.12
External References
Related Security Bulletins
- Path traversal in Jira Data Center
- Path traversal in Bitbucket Data Center
- Path traversal in Confluence Data Center
- Path traversal in Jira Service Management Data Center
- Path traversal in Bamboo Data Center
- Path traversal in Crowd Data Center
- Path traversal in Atlassian Crucible
- Path traversal in Atlassian Fisheye