Skip to main content
Background

CVE-2026-21589: Critical Arbitrary File Read Vulnerability in Atlassian Products

Share

On October 5, 2026, Atlassian released a security advisory to address a critical arbitrary file read vulnerability across multiple Atlassian Data Center products, including Bitbucket, Confluence, Jira Software, and Bamboo. CVE-2026-21589 carries a maximum CVSS v4.0 score of 9.3. The vulnerability stems from a path traversal flaw.

An unauthenticated remote attacker could exploit this vulnerability to read specific files within the web application root directory of affected Atlassian products. Although the vulnerability does not allow directory enumeration, attackers with knowledge of exact filenames could access sensitive information, such as configuration files containing plain-text credentials.

The patch is available immediately, and Atlassian has urged self-hosted users to upgrade to fixed releases as soon as possible. Cloud users are not affected as Atlassian has already applied fixes.

Mitigation with Akamai App & API Protector

Akamai App & API Protector customers are protected because we have released security updates to address this CVE and monitor for exploitation attempts. 

  • Adaptive Security Engine: 3000990 v1 — Atlassian Pre-Auth Arbitrary File Read Detected (CVE-2026-21589)

The most effective defense continues to be the prompt application of vendor patches. For organizations that cannot patch immediately, applying web application firewall rules as recommended by Atlassian is critical to block path traversal and directory traversal attempts.

Stay tuned

The Akamai Security Intelligence Group will continue to monitor, report on, and create mitigations for threats such as these for both our customers and the security community at large. To keep up with more breaking news from the Akamai Security Intelligence Group, check out our research home page and follow us on social media.

About the Author(s)

Akamai Wave Blue

Akamai Security Intelligence Group

Akamai SIG is a global team of world-class researchers, engineers, strategists, and data scientists with a broad range of expertise and security disciplines. Our data sources include the enormous Akamai Cloud, open sources, collaboration with third parties, and dark web intelligence. We have also developed our own algorithms and tools that help us deliver our research and keep Akamai security solutions up to date.