IT administrators managing on-premise Atlassian deployments must immediately address a critical 9.3 CVSS vulnerability that exposes sensitive files to unauthenticated attackers. Tracked as CVE-2026-21589, this flaw allows external actors to read files directly from the web root directories of Jira Software Data Center and Confluence Data Center without requiring a valid account or login credentials.
According to Atlassian advisories, exploiting this vulnerability requires the attacker to know the exact filename and path of the targeted resource. The flaw does not facilitate directory enumeration, meaning hackers cannot automatically list or discover hidden files. However, installations that store sensitive configuration files or backups in accessible application directories face a severe exposure risk.
While the Confluence advisory categorizes the issue under path traversal with an "Arbitrary Read/Write" classification, the published technical description confirms it is limited to unauthenticated file access. There is currently no indication that attackers can modify files or execute malicious code through this specific vector.
How to Secure Your Atlassian Deployments
Organizations using customer-managed Data Center deployments must prioritize patching, as exploitation does not require user authentication. Atlassian indicates that all versions prior to the newly released fixes are vulnerable. Cloud customers do not need to take action, as Atlassian has already implemented patches for its hosted products and found no evidence of exploitation.
- Update Jira Data Center: Install versions 9.12.40, 10.3.26, or 11.3.12 to permanently resolve the vulnerability.
- Update Confluence Data Center: Upgrade to versions 9.2.26 or 10.2.19. Organizations on older, unsupported releases must move to a patched long-term support release.
- Restrict Network Access: If immediate patching is impossible, administrators should remove affected instances from the public internet and restrict external network access entirely.
For environments that must remain online, Atlassian recommends implementing a web application firewall (WAF) or reverse proxy rule to block suspicious traversal patterns. Administrators can use a regular expression to detect double dots immediately adjacent to forward slashes, backslashes, or double colons, ensuring they account for URL-encoded variants.
Alternatively, teams can utilize Apache Tomcat’s RewriteValve. This requires shutting down each cluster node, enabling the valve in the application’s Context element within the conf/server.xml file, and appending Atlassian’s supplied rewrite.config file to the WEB-INF directory for either Jira or Confluence before restarting.
The Danger of Web Root Exposure
The discrepancy between the "Arbitrary Read/Write" classification and the actual read-only capability of CVE-2026-21589 might tempt some security teams to deprioritize the patch. However, the 9.3 CVSS score accurately reflects the reality of legacy enterprise deployments. Web root directories in older, heavily customized Jira and Confluence environments frequently accumulate forgotten diagnostic logs, temporary backup files, or custom scripts containing hardcoded credentials.
Because the vulnerability requires attackers to know the exact file path, the immediate threat comes from automated scanning tools programmed to blindly request standard configuration filenames across exposed IP addresses. The Tomcat RewriteValve mitigation is a clever stopgap, but it introduces operational overhead and potential routing conflicts if not tested thoroughly across all cluster nodes. Ultimately, removing these instances from the public internet is the only foolproof defense until the official patches are applied.