endoflife.ai
Atlassian Data Center Jira Software Confluence Bitbucket

Atlassian CVE-2026-21589: Fixed Builds Only on LTS and Newest Lines

By Scott Bissett  ·  Published: October 6, 2026  ·  EOL Watch — news analysis  ·  Read at Atlassian's security advisory on October 6, 2026; lifecycle dates from Atlassian's end-of-life policy as served on our Atlassian Data Center pages.

One flaw, eight Data Center products, and fixed builds on only the LTS and newest lines. Atlassian's advisory CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products, published October 5, 2026, describes a flaw that "allows an unauthenticated attacker to access specific files within the web application root directory in affected versions". Atlassian "rates the severity level of this vulnerability as Critical (9.3)", vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H. The affected-versions column reads the same for every product: "All versions are affected". The fixed-versions column does not. For each product it names builds on the LTS lines and on the newest line, and nothing else. Every other feature line that Atlassian still supports today has no fixed build named by Atlassian, and the advisory's instruction for it is an upgrade.

Quick answer: Atlassian's advisory for CVE-2026-21589 says all versions of Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye Data Center are affected, and names fixed builds only on the LTS and newest lines: Jira Software 9.12.40, 10.3.26 and 11.3.12; Jira Service Management 5.12.40, 10.3.26 and 11.3.12; Confluence 9.2.26 and 10.2.19; Bitbucket 9.4.26, 10.2.8 and 10.5.1; Bamboo 10.2.24 and 12.1.12; Crowd 6.3.7, 7.0.3, 7.1.7 and 7.2.4; Crucible and Fisheye 4.9.15. A supported installation on any other line, for example Jira Software 10.1, which reaches end of support on October 9, 2026, has no fixed build and must move to a fixed line; until then Atlassian's mitigation is to take the instance off the internet and apply its WAF, Tomcat RewriteValve or urlrewrite.xml rule.
On exploitation, read the sentence carefully. The advisory's only statement about exploitation is about Cloud: "Affected Atlassian Cloud products have been patched, and our investigation has not found evidence of exploitation. No Cloud customer action is required." It makes no statement either way about exploitation of Data Center instances. What it does say about them is that "All Data Center products listed below are at risk and require immediate attention." The flaw is limited in one way the advisory spells out: "Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents." It then adds: "In some configurations, there may be sensitive files present that increase your risk."

Fixed lines and unfixed lines, product by product

The Affected and Fixed columns are Atlassian's, copied from the advisory. The last two columns are ours: the feature lines Atlassian's end-of-life policy still lists as supported today that have no fixed build in the advisory, and the earliest end-of-support date among them, as served on our product pages. Lines whose support already ended are not listed; an installation on one of those has two reasons to move, not one. Atlassian's own instruction above the table is "Atlassian recommends patching to the fixed LTS version or later."

Jira

ProductAffectedFixed build(s)Lines with no fixed buildNearest line end
Jira Software Data CenterAll versions are affected9.12.40, 10.3.26, 11.3.1210.1, 10.2, 10.4, 10.5, 10.6, 10.7, 11.0, 11.1, 11.210.1: October 9, 2026
Jira Service Management Data CenterAll versions are affected5.12.40, 10.3.26, 11.3.1210.1, 10.2, 10.4, 10.5, 10.6, 10.7, 11.0, 11.1, 11.210.1: October 9, 2026

Jira Software 10.1 ends this week, on October 9, 2026, and 10.2 follows on November 20, 2026. The 10.3 LTS line itself ends on December 5, 2026, so an installation that moves from 10.1 or 10.2 to 10.3.26 for this fix has another move inside two months. 11.3 is both the current LTS and the newest line; its end of support is December 3, 2027. The 9.12 and 5.12 builds are the odd ones out: Atlassian's end-of-life policy table no longer lists either line, and our page serves 9.12's end of support as November 29, 2025. The advisory lists 9.12.40 and 5.12.40 without comment.

Confluence

ProductAffectedFixed build(s)Lines with no fixed buildNearest line end
Confluence Data CenterAll versions are affected9.2.26, 10.2.199.3, 9.4, 9.5, 10.0, 10.19.3: February 4, 2027

Confluence 9.1 is not in the table because its support ended on October 3, 2026, two days before the advisory. The 9.2 LTS line ends on December 10, 2026; 10.2, the current LTS and newest line, ends on December 2, 2027.

Bitbucket

ProductAffectedFixed build(s)Lines with no fixed buildNearest line end
Bitbucket Data CenterAll versions are affected9.4.26, 10.2.8, 10.5.19.3, 9.5, 9.6, 10.0, 10.1, 10.3, 10.49.3: October 29, 2026

Bitbucket is the one product where the newest line is not an LTS: 10.5.1 is a fixed build on the 10.5 feature line, which shipped so recently that Atlassian's end-of-life policy table does not yet list an end date for it. The two LTS lines end on December 3, 2026 for 9.4 and March 3, 2028 for 10.2. Note the gap: 10.3 and 10.4 are newer than the 10.2 LTS and still supported into 2028, and neither has a fixed build.

Bamboo

ProductAffectedFixed build(s)Lines with no fixed buildNearest line end
Bamboo Data CenterAll versions are affected10.2.24, 12.1.1210.1, 11.0, 12.010.1: November 20, 2026

Bamboo 10.2 LTS ends on December 20, 2026; 12.1, the current LTS and newest line, ends on December 17, 2027.

Crowd, Crucible and Fisheye

ProductAffectedFixed build(s)Lines with no fixed buildNearest line end
Crowd Data CenterAll versions are affected6.3.7, 7.0.3, 7.1.7, 7.2.4Not tracked hereNot tracked here
CrucibleAll versions are affected4.9.15Not tracked hereNot tracked here
FisheyeAll versions are affected4.9.15Not tracked hereNot tracked here

We do not serve lifecycle data for Crowd, Crucible or Fisheye, so the last two columns are left empty rather than filled from memory. The fixed builds are Atlassian's, from the advisory.

Running Atlassian Data Center past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers Atlassian Data Center is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

Why a supported line can have no fixed build

Atlassian's end-of-life policy supports each feature release and each LTS release for two years, and its advisory practice is to ship security fixes on the LTS lines and the newest line. CVE-2026-21589 is a clean example of what that means for the lines in between. Jira Software 10.4 through 11.2 are all inside their two-year windows, all affected, and none has a build. The advisory does not say those lines will not be fixed later; it names the builds it has, and for everything else its instruction is to "patch each of your affected installations to fixed versions or the latest version". Read that as the fixed builds named by Atlassian today, not as a promise about any other line.

What we are not saying. We are not saying Jira Software 10.4, Confluence 10.1 or Bitbucket 10.4 are end of life; Atlassian's policy lists each as supported, and the dates above are the ones it publishes. We are not saying Atlassian will never ship a build for them; the advisory is silent on that. And we are not adding any of these products to our Exploited & Unpatchable feed: that feed lists exploited flaws on products past their end date, and the advisory makes no exploitation claim about Data Center. What an operator on an unfixed line needs to know this week is narrower: the fix for your installation is a different line, and Atlassian's mitigation is the only thing available to you until you make that move.

Atlassian's temporary mitigations

The advisory's section "Apply temporary mitigations if unable to patch" opens with: "Remove your instance from the internet until you can patch or apply mitigations, if possible. Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action." It then gives three options:

We have not reproduced the regex or the configuration blocks: a character dropped in copying would defeat the rule. Take them from the advisory.

What to do, by line

On an LTS or newest line (Jira 9.12, 5.12, 10.3, 11.3; Confluence 9.2, 10.2; Bitbucket 9.4, 10.2, 10.5; Bamboo 10.2, 12.1; Crowd 6.3, 7.0, 7.1, 7.2; Crucible and Fisheye 4.9): install the fixed build the advisory names for your line. Apply the mitigation until the change window arrives.

On any other supported line: apply the mitigation now, then choose the destination line, and choose it with the end dates in view. For Jira, moving to 10.3.26 buys a fix on a line that ends on December 5, 2026; moving to 11.3.12 lands on a line supported until December 3, 2027. For Confluence the same choice is 9.2.26, ending December 10, 2026, against 10.2.19, ending December 2, 2027. For Bitbucket 10.3 and 10.4 the fixed lines are 10.2.8, an older LTS ending March 3, 2028, or 10.5.1, the newest line. For Bamboo 12.0 the fixed lines are 12.1.12 or 10.2.24.

On a line whose support has already ended (for example Jira Software 10.0, Confluence 9.1, Bitbucket 9.2): the advisory says all versions are affected, so the installation is exposed, and no fixed build exists on its line. Apply the mitigation, and treat the move to a fixed LTS line as overdue rather than new.

Frequently Asked Questions

Is there a patch for Atlassian CVE-2026-21589?

Yes, on specific lines. Atlassian's advisory names the fixed builds as Bitbucket Data Center 9.4.26, 10.2.8 and 10.5.1; Confluence Data Center 9.2.26 and 10.2.19; Jira Service Management Data Center 5.12.40, 10.3.26 and 11.3.12; Jira Software Data Center 9.12.40, 10.3.26 and 11.3.12; Bamboo Data Center 10.2.24 and 12.1.12; Crowd Data Center 6.3.7, 7.0.3, 7.1.7 and 7.2.4; and Crucible and Fisheye 4.9.15. An installation on any other line has no fixed build named by Atlassian and must move to one of these lines.

Which Jira lines get no fixed build for CVE-2026-21589?

For Jira Software Data Center and Jira Service Management Data Center the fixed builds are on 9.12 and 5.12, 10.3 and 11.3. The supported feature lines 10.1, 10.2, 10.4, 10.5, 10.6, 10.7, 11.0, 11.1 and 11.2 have no fixed build named by Atlassian; the advisory says all versions are affected. On Atlassian's end-of-life policy, Jira Software 10.1 reaches end of support on October 9, 2026 and 10.2 on November 20, 2026, so an installation on either line has an upgrade ahead of it in any case.

Is CVE-2026-21589 being exploited?

Atlassian's advisory makes one statement about exploitation, and it is about its Cloud products: affected Atlassian Cloud products have been patched, and its investigation has not found evidence of exploitation. The advisory makes no statement either way about exploitation of Data Center instances; it says all Data Center products listed are at risk and require immediate attention. Exploitation requires prior knowledge of the target file's exact name and path, and the flaw does not allow an attacker to list directory contents.

What is Atlassian's mitigation for CVE-2026-21589 if I cannot patch?

Atlassian's first instruction is to remove the instance from the internet until you can patch or apply mitigations, and it says instances accessible to the public internet, including those with user authentication, should be restricted from external network access. It then gives three options: a Web Application Firewall rule using the regex pattern printed in the advisory, for all affected products; blocking requests with Tomcat's RewriteValve, for Confluence, Jira Service Management, Jira, Bamboo and Crowd; or adding a rule to urlrewrite.xml, for Bitbucket only. The advisory prints the exact regex and configuration; copy it from there.

Why does Jira Software 9.12 get a fixed build when it is past end of support?

Atlassian's advisory names 9.12.40 for Jira Software and 5.12.40 for Jira Service Management, and Atlassian's end-of-life policy table no longer lists either line. Our Jira Software page serves the end of support for 9.12 as November 29, 2025, two years after its first release under Atlassian's two-year rule. The advisory does not explain why a build was issued for a line past that date; it simply lists it. Treat 9.12.40 as a fix for installations still on that line, not as an extension of the line's support.

Related

© 2026 endoflife.ai · How we verify our dates · API · About