Path traversal in Jira Software Data Center - CVE-2026-21589

 

Path traversal in Jira Software Data Center - CVE-2026-21589

Published: October 6, 2026


Vulnerability identifier: #VU153326
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-21589
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to read files within the web application root directory.

The vulnerability exists due to improper limitation of a pathname to a restricted directory in Jira Data Center when handling requests containing path traversal sequences. A remote attacker can send a specially crafted request to read files within the web application root directory.

Exploitation requires prior knowledge of the target file's exact name and path, and directory contents cannot be enumerated.


Affected software

Jira Software Data Center
Fisheye
Crucible Data Center
Jira Service Management Data Center
Crowd Data Center
Confluence Data Center
Bitbucket Data Center
Bamboo Data Center
Crowd Server

How to mitigate CVE-2026-21589

Install security update from vendor's website.

Jira Software Data Center - addressed in versions 9.12.40, 10.3.26, 11.3.12
Fisheye - update to 4.9.15
Crucible Data Center - update to 4.9.15
Jira Service Management Data Center - addressed in versions 5.12.40, 10.3.26, 11.3.12
Crowd Data Center - addressed in versions 6.3.7, 7.0.3, 7.1.7, 7.2.4
Crowd Server - addressed in versions 6.3.7, 7.0.3, 7.1.7, 7.2.4
Confluence Data Center - addressed in versions 9.2.26, 10.2.19
Bitbucket Data Center - addressed in versions 9.4.26, 10.2.8, 10.5.1
Bamboo Data Center - addressed in versions 10.2.24, 12.1.12

External References

Related Security Bulletins