Atlassian CVE-2026-21589: Fixed Builds Only on LTS and Newest Lines
One flaw, eight Data Center products, and fixed builds on only the LTS and newest lines. Atlassian's advisory CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products, published October 5, 2026, describes a flaw that "allows an unauthenticated attacker to access specific files within the web application root directory in affected versions". Atlassian "rates the severity level of this vulnerability as Critical (9.3)", vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H. The affected-versions column reads the same for every product: "All versions are affected". The fixed-versions column does not. For each product it names builds on the LTS lines and on the newest line, and nothing else. Every other feature line that Atlassian still supports today has no fixed build named by Atlassian, and the advisory's instruction for it is an upgrade.
Fixed lines and unfixed lines, product by product
The Affected and Fixed columns are Atlassian's, copied from the advisory. The last two columns are ours: the feature lines Atlassian's end-of-life policy still lists as supported today that have no fixed build in the advisory, and the earliest end-of-support date among them, as served on our product pages. Lines whose support already ended are not listed; an installation on one of those has two reasons to move, not one. Atlassian's own instruction above the table is "Atlassian recommends patching to the fixed LTS version or later."
Jira
| Product | Affected | Fixed build(s) | Lines with no fixed build | Nearest line end |
|---|---|---|---|---|
| Jira Software Data Center | All versions are affected | 9.12.40, 10.3.26, 11.3.12 | 10.1, 10.2, 10.4, 10.5, 10.6, 10.7, 11.0, 11.1, 11.2 | 10.1: October 9, 2026 |
| Jira Service Management Data Center | All versions are affected | 5.12.40, 10.3.26, 11.3.12 | 10.1, 10.2, 10.4, 10.5, 10.6, 10.7, 11.0, 11.1, 11.2 | 10.1: October 9, 2026 |
Jira Software 10.1 ends this week, on October 9, 2026, and 10.2 follows on November 20, 2026. The 10.3 LTS line itself ends on December 5, 2026, so an installation that moves from 10.1 or 10.2 to 10.3.26 for this fix has another move inside two months. 11.3 is both the current LTS and the newest line; its end of support is December 3, 2027. The 9.12 and 5.12 builds are the odd ones out: Atlassian's end-of-life policy table no longer lists either line, and our page serves 9.12's end of support as November 29, 2025. The advisory lists 9.12.40 and 5.12.40 without comment.
Confluence
| Product | Affected | Fixed build(s) | Lines with no fixed build | Nearest line end |
|---|---|---|---|---|
| Confluence Data Center | All versions are affected | 9.2.26, 10.2.19 | 9.3, 9.4, 9.5, 10.0, 10.1 | 9.3: February 4, 2027 |
Confluence 9.1 is not in the table because its support ended on October 3, 2026, two days before the advisory. The 9.2 LTS line ends on December 10, 2026; 10.2, the current LTS and newest line, ends on December 2, 2027.
Bitbucket
| Product | Affected | Fixed build(s) | Lines with no fixed build | Nearest line end |
|---|---|---|---|---|
| Bitbucket Data Center | All versions are affected | 9.4.26, 10.2.8, 10.5.1 | 9.3, 9.5, 9.6, 10.0, 10.1, 10.3, 10.4 | 9.3: October 29, 2026 |
Bitbucket is the one product where the newest line is not an LTS: 10.5.1 is a fixed build on the 10.5 feature line, which shipped so recently that Atlassian's end-of-life policy table does not yet list an end date for it. The two LTS lines end on December 3, 2026 for 9.4 and March 3, 2028 for 10.2. Note the gap: 10.3 and 10.4 are newer than the 10.2 LTS and still supported into 2028, and neither has a fixed build.
Bamboo
| Product | Affected | Fixed build(s) | Lines with no fixed build | Nearest line end |
|---|---|---|---|---|
| Bamboo Data Center | All versions are affected | 10.2.24, 12.1.12 | 10.1, 11.0, 12.0 | 10.1: November 20, 2026 |
Bamboo 10.2 LTS ends on December 20, 2026; 12.1, the current LTS and newest line, ends on December 17, 2027.
Crowd, Crucible and Fisheye
| Product | Affected | Fixed build(s) | Lines with no fixed build | Nearest line end |
|---|---|---|---|---|
| Crowd Data Center | All versions are affected | 6.3.7, 7.0.3, 7.1.7, 7.2.4 | Not tracked here | Not tracked here |
| Crucible | All versions are affected | 4.9.15 | Not tracked here | Not tracked here |
| Fisheye | All versions are affected | 4.9.15 | Not tracked here | Not tracked here |
We do not serve lifecycle data for Crowd, Crucible or Fisheye, so the last two columns are left empty rather than filled from memory. The fixed builds are Atlassian's, from the advisory.
Why a supported line can have no fixed build
Atlassian's end-of-life policy supports each feature release and each LTS release for two years, and its advisory practice is to ship security fixes on the LTS lines and the newest line. CVE-2026-21589 is a clean example of what that means for the lines in between. Jira Software 10.4 through 11.2 are all inside their two-year windows, all affected, and none has a build. The advisory does not say those lines will not be fixed later; it names the builds it has, and for everything else its instruction is to "patch each of your affected installations to fixed versions or the latest version". Read that as the fixed builds named by Atlassian today, not as a promise about any other line.
Atlassian's temporary mitigations
The advisory's section "Apply temporary mitigations if unable to patch" opens with: "Remove your instance from the internet until you can patch or apply mitigations, if possible. Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action." It then gives three options:
- "Option 1: Apply a Web Application Firewall Rule, requires regex filtering (For All Affected Products)". Atlassian prints a regex to block at the WAF or proxy layer and explains it: "The intent of this regex is to block .. immediately adjacent to / , \ , or ::". It asks you to test that the rule also handles the URL-encoded forms.
- "Option 2: Block requests using Tomcat’s RewriteValve (For Confluence, JSM, Jira, Bamboo, and Crowd)". Per node: shut the node down, enable the RewriteValve in
conf/server.xml(for Crowd, in the Tomcat file that holds the application<Context>), and add the rewrite configuration the advisory prints. - "Option 3: Add rule to urlrewrite.xml (For Bitbucket only)". Add the printed
<rule>to the top ofapp/WEB-INF/urlrewrite.xml, on every node and on every mirror and mirror-farm node.
We have not reproduced the regex or the configuration blocks: a character dropped in copying would defeat the rule. Take them from the advisory.
What to do, by line
On an LTS or newest line (Jira 9.12, 5.12, 10.3, 11.3; Confluence 9.2, 10.2; Bitbucket 9.4, 10.2, 10.5; Bamboo 10.2, 12.1; Crowd 6.3, 7.0, 7.1, 7.2; Crucible and Fisheye 4.9): install the fixed build the advisory names for your line. Apply the mitigation until the change window arrives.
On any other supported line: apply the mitigation now, then choose the destination line, and choose it with the end dates in view. For Jira, moving to 10.3.26 buys a fix on a line that ends on December 5, 2026; moving to 11.3.12 lands on a line supported until December 3, 2027. For Confluence the same choice is 9.2.26, ending December 10, 2026, against 10.2.19, ending December 2, 2027. For Bitbucket 10.3 and 10.4 the fixed lines are 10.2.8, an older LTS ending March 3, 2028, or 10.5.1, the newest line. For Bamboo 12.0 the fixed lines are 12.1.12 or 10.2.24.
On a line whose support has already ended (for example Jira Software 10.0, Confluence 9.1, Bitbucket 9.2): the advisory says all versions are affected, so the installation is exposed, and no fixed build exists on its line. Apply the mitigation, and treat the move to a fixed LTS line as overdue rather than new.
Frequently Asked Questions
Is there a patch for Atlassian CVE-2026-21589?
Yes, on specific lines. Atlassian's advisory names the fixed builds as Bitbucket Data Center 9.4.26, 10.2.8 and 10.5.1; Confluence Data Center 9.2.26 and 10.2.19; Jira Service Management Data Center 5.12.40, 10.3.26 and 11.3.12; Jira Software Data Center 9.12.40, 10.3.26 and 11.3.12; Bamboo Data Center 10.2.24 and 12.1.12; Crowd Data Center 6.3.7, 7.0.3, 7.1.7 and 7.2.4; and Crucible and Fisheye 4.9.15. An installation on any other line has no fixed build named by Atlassian and must move to one of these lines.
Which Jira lines get no fixed build for CVE-2026-21589?
For Jira Software Data Center and Jira Service Management Data Center the fixed builds are on 9.12 and 5.12, 10.3 and 11.3. The supported feature lines 10.1, 10.2, 10.4, 10.5, 10.6, 10.7, 11.0, 11.1 and 11.2 have no fixed build named by Atlassian; the advisory says all versions are affected. On Atlassian's end-of-life policy, Jira Software 10.1 reaches end of support on October 9, 2026 and 10.2 on November 20, 2026, so an installation on either line has an upgrade ahead of it in any case.
Is CVE-2026-21589 being exploited?
Atlassian's advisory makes one statement about exploitation, and it is about its Cloud products: affected Atlassian Cloud products have been patched, and its investigation has not found evidence of exploitation. The advisory makes no statement either way about exploitation of Data Center instances; it says all Data Center products listed are at risk and require immediate attention. Exploitation requires prior knowledge of the target file's exact name and path, and the flaw does not allow an attacker to list directory contents.
What is Atlassian's mitigation for CVE-2026-21589 if I cannot patch?
Atlassian's first instruction is to remove the instance from the internet until you can patch or apply mitigations, and it says instances accessible to the public internet, including those with user authentication, should be restricted from external network access. It then gives three options: a Web Application Firewall rule using the regex pattern printed in the advisory, for all affected products; blocking requests with Tomcat's RewriteValve, for Confluence, Jira Service Management, Jira, Bamboo and Crowd; or adding a rule to urlrewrite.xml, for Bitbucket only. The advisory prints the exact regex and configuration; copy it from there.
Why does Jira Software 9.12 get a fixed build when it is past end of support?
Atlassian's advisory names 9.12.40 for Jira Software and 5.12.40 for Jira Service Management, and Atlassian's end-of-life policy table no longer lists either line. Our Jira Software page serves the end of support for 9.12 as November 29, 2025, two years after its first release under Atlassian's two-year rule. The advisory does not explain why a build was issued for a line past that date; it simply lists it. Treat 9.12.40 as a fix for installations still on that line, not as an extension of the line's support.
Related
- Atlassian Data Center — every product line with Atlassian's end-of-support dates
- Jira Software and Jira Service Management — line by line, with the LTS lines marked
- Confluence, Bitbucket and Bamboo — the other three products with lifecycle data on this site
- Atlassian Server and Data Center end of life — how the two-year policy and the LTS lines work
- Exploited & Unpatchable — the feed of KEV entries on products past their fix window
- How we verify our dates — the rules every number on this site is held to