{
    "file_item": {
        "filepath": "security-advisories",
        "filename": "CERT-EU-SA2026-015.pdf"
    },
    "title": "Critical Vulnerability in Multiple Atlassian Products",
    "serial_number": "2026-015",
    "publish_date": "07-10-2026 07:52:48",
    "description": "On 5 October 2026, Atlassian published a security advisory addressing a critical arbitrary file access vulnerability. It affects Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.<br>\nCERT-EU strongly recommends upgrading all affected installations to a fixed version as soon as possible, starting with instances accessible from the internet. CERT-EU also recommends checking access logs for signs of exploitation.<br>\n",
    "url_title": "2026-015",
    "content_markdown": "---\ntitle: 'Critical Vulnerability in\u00a0Multiple\u00a0Atlassian\u00a0Products'\nnumber: '2026-015'\nversion: '1.0'\noriginal_date: '2026-10-05'\ndate: '2026-10-06'\n---\n\n_History:_\n\n* _06/10/2026 --- v1.0 -- Initial publication_\n\n# Summary\n\nOn 5 October 2026, Atlassian published a security advisory addressing a **critical arbitrary file access** vulnerability. It affects **Bitbucket Data Center**, **Confluence Data Center**, **Jira Service Management Data Center**, **Jira Software Data Center**, **Bamboo Data Center**, **Crowd Data Center**, **Crucible** and **Fisheye** [1].\n\nCERT-EU strongly recommends upgrading all affected installations to a fixed version as soon as possible, starting with instances accessible from the internet. CERT-EU also recommends checking access logs for signs of exploitation.\n\n# Technical Details\n\nThe vulnerability\u00a0**CVE-2026-21589**, with a CVSS score of 9.3, is an **arbitrary file access** vulnerability that allows an unauthenticated attacker to access specific files within the web application root directory [1].\n\nTo exploit the vulnerability, an attacker needs to know the target file's exact name and path in advance. The vulnerability does not allow attackers to enumerate or list directory contents. Atlassian notes that some configurations may contain sensitive files that increase the risk [1].\n\n# Affected Products\n\nAll versions earlier than the fixed versions listed below are affected [1]:\n\n| Product | Fixed Versions |\n|---|---|\n| Bitbucket Data Center | 9.4.26, 10.2.8, 10.5.1 |\n| Confluence Data Center | 9.2.26, 10.2.19 |\n| Jira Service Management Data Center | 5.12.40, 10.3.26, 11.3.12 |\n| Jira Software Data Center | 9.12.40, 10.3.26, 11.3.12 |\n| Bamboo Data Center | 10.2.24, 12.1.12 |\n| Crowd Data Center | 6.3.7, 7.0.3, 7.1.7, 7.2.4 |\n| Crucible | 4.9.15 |\n| Fisheye | 4.9.15 |\n\nAtlassian states that affected Atlassian Cloud products have been patched and that its investigation has not found evidence of exploitation [1].\n\nAdditional information is available in the vendor's advisory [1].\n\n# Recommendations\n\nCERT-EU strongly recommends upgrading all affected installations to a fixed version or the latest version as soon as possible, starting with internet-facing instances. Atlassian recommends patching to the fixed LTS version or later [1]. CERT-EU also recommends checking access logs for signs of exploitation.\n\n## Mitigation\n\nIf patching is not immediately possible, **remove the instance from the internet until it can be patched or mitigated** (this includes instances accessible from the public internet that require user authentication) [1], or:\n\n- **Option 1 (all affected products):** apply a rule on the Web Application Firewall or proxy layer that blocks any URL matching the regular expression below. Then test that the rule blocks `..` immediately adjacent to `/`, `\\`, or `::`, including URL-encoded forms [1].\n\n```none\n(?is).*(?:/|\\\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\\.|%(?:25)*2e){2}(?:/|\\\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).*\n```\n\n- **Option 2 (Confluence, Jira Service Management, Jira, Bamboo and Crowd):** on each node, enable Tomcat's RewriteValve in the application `<Context>` element and install a `rewrite.config` file in the `WEB-INF` directory to block such requests [1].\n- **Option 3 (Bitbucket only):** add a blocking rule at the top of `./app/WEB-INF/urlrewrite.xml` on all nodes, mirrors and mirror farm nodes, then restart Bitbucket Data Center [1].\n\nBack up the instance before applying Option 2 or Option 3. The exact configuration snippets are in the vendor's advisory [1].\n\n## Compromise assessment\n\nCERT-EU recommends checking all affected instances for evidence of compromise. To investigate access logs, Atlassian suggests one of these approaches [1]:\n\n- URL-decode each access-log request line, then check for `..` immediately adjacent to `/`, `\\`, or `::` [1].\n- Search raw (non-decoded) log lines directly with the regular expression shown above [1].\n\nIf a compromise is suspected, CERT-EU recommends investigating the affected instances, reviewing and rotating any credentials or secrets that may have been exposed, and contacting the relevant cybersecurity authority.\n\n# References\n\n[1] <https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html>\n",
    "content_html": "<p><em>History:</em></p><ul><li><em>06/10/2026 --- v1.0 -- Initial publication</em></li></ul><h2 id=\"summary\">Summary</h2><p>On 5 October 2026, Atlassian published a security advisory addressing a <strong>critical arbitrary file access</strong> vulnerability. It affects <strong>Bitbucket Data Center</strong>, <strong>Confluence Data Center</strong>, <strong>Jira Service Management Data Center</strong>, <strong>Jira Software Data Center</strong>, <strong>Bamboo Data Center</strong>, <strong>Crowd Data Center</strong>, <strong>Crucible</strong> and <strong>Fisheye</strong> [1].</p><p>CERT-EU strongly recommends upgrading all affected installations to a fixed version as soon as possible, starting with instances accessible from the internet. CERT-EU also recommends checking access logs for signs of exploitation.</p><h2 id=\"technical-details\">Technical Details</h2><p>The vulnerability\u00a0<strong>CVE-2026-21589</strong>, with a CVSS score of 9.3, is an <strong>arbitrary file access</strong> vulnerability that allows an unauthenticated attacker to access specific files within the web application root directory [1].</p><p>To exploit the vulnerability, an attacker needs to know the target file's exact name and path in advance. The vulnerability does not allow attackers to enumerate or list directory contents. Atlassian notes that some configurations may contain sensitive files that increase the risk [1].</p><h2 id=\"affected-products\">Affected Products</h2><p>All versions earlier than the fixed versions listed below are affected [1]:</p><table><thead><tr><th>Product</th><th>Fixed Versions</th></tr></thead><tbody><tr><td>Bitbucket Data Center</td><td>9.4.26, 10.2.8, 10.5.1</td></tr><tr><td>Confluence Data Center</td><td>9.2.26, 10.2.19</td></tr><tr><td>Jira Service Management Data Center</td><td>5.12.40, 10.3.26, 11.3.12</td></tr><tr><td>Jira Software Data Center</td><td>9.12.40, 10.3.26, 11.3.12</td></tr><tr><td>Bamboo Data Center</td><td>10.2.24, 12.1.12</td></tr><tr><td>Crowd Data Center</td><td>6.3.7, 7.0.3, 7.1.7, 7.2.4</td></tr><tr><td>Crucible</td><td>4.9.15</td></tr><tr><td>Fisheye</td><td>4.9.15</td></tr></tbody></table><p>Atlassian states that affected Atlassian Cloud products have been patched and that its investigation has not found evidence of exploitation [1].</p><p>Additional information is available in the vendor's advisory [1].</p><h2 id=\"recommendations\">Recommendations</h2><p>CERT-EU strongly recommends upgrading all affected installations to a fixed version or the latest version as soon as possible, starting with internet-facing instances. Atlassian recommends patching to the fixed LTS version or later [1]. CERT-EU also recommends checking access logs for signs of exploitation.</p><h3 id=\"mitigation\">Mitigation</h3><p>If patching is not immediately possible, <strong>remove the instance from the internet until it can be patched or mitigated</strong> (this includes instances accessible from the public internet that require user authentication) [1], or:</p><ul><li><strong>Option 1 (all affected products):</strong> apply a rule on the Web Application Firewall or proxy layer that blocks any URL matching the regular expression below. Then test that the rule blocks <code>..</code> immediately adjacent to <code>/</code>, <code>\\</code>, or <code>::</code>, including URL-encoded forms [1].</li></ul><pre><code>(?is).*(?:/|\\\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\\.|%(?:25)*2e){2}(?:/|\\\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).*\n</code></pre><ul><li><strong>Option 2 (Confluence, Jira Service Management, Jira, Bamboo and Crowd):</strong> on each node, enable Tomcat's RewriteValve in the application <code>&lt;Context&gt;</code> element and install a <code>rewrite.config</code> file in the <code>WEB-INF</code> directory to block such requests [1].</li><li><strong>Option 3 (Bitbucket only):</strong> add a blocking rule at the top of <code>./app/WEB-INF/urlrewrite.xml</code> on all nodes, mirrors and mirror farm nodes, then restart Bitbucket Data Center [1].</li></ul><p>Back up the instance before applying Option 2 or Option 3. The exact configuration snippets are in the vendor's advisory [1].</p><h3 id=\"compromise-assessment\">Compromise assessment</h3><p>CERT-EU recommends checking all affected instances for evidence of compromise. To investigate access logs, Atlassian suggests one of these approaches [1]:</p><ul><li>URL-decode each access-log request line, then check for <code>..</code> immediately adjacent to <code>/</code>, <code>\\</code>, or <code>::</code> [1].</li><li>Search raw (non-decoded) log lines directly with the regular expression shown above [1].</li></ul><p>If a compromise is suspected, CERT-EU recommends investigating the affected instances, reviewing and rotating any credentials or secrets that may have been exposed, and contacting the relevant cybersecurity authority.</p><h2 id=\"references\">References</h2><p>[1] <a rel=\"noopener\" target=\"_blank\" href=\"https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html\">https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html</a></p>",
    "licence": {
        "title": "Creative Commons Attribution 4.0 International (CC-BY 4.0)",
        "link": "https://creativecommons.org/licenses/by/4.0/",
        "restrictions": "https://cert.europa.eu/legal-notice",
        "author": "The Cybersecurity Service for the Union institutions, bodies, offices and agencies"
    }
}