CVE-2026-21589
h2. Summary of Vulnerability *All Jira Service Management Data Center versions are affected by this vulnerability.* This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be sensitive files present that increase your risk. Jira Service Management Data Center versions as listed below are at risk and require immediate attention. See *‘What You Need to Do’* for detailed instructions. {panel:bgColor=#deebff} Affected Atlassian Cloud products have been patched, and our investigation has not found any evidence of exploitation. No Cloud customer action is required. {panel} This critical severity Arbitrary File Access vulnerability known as CVE-2026-21589 affects all versions prior to the listed fix versions of Jira Service Management Data Center. Versions outside of the support window (i.e. versions that have reached End of Life) may also be affected, so Atlassian recommends you upgrade to a fixed LTS version or later. h2. Affected Versions ||Product||Affected Versions|| |Jira Service Management Data Center|All versions are affected| h2. Fixed Versions ||Product||Fixed Versions|| |Jira Service Management Data Center| - 5.12.40 - 10.3.26 - 11.3.12| h2. What You Need to Do h3. Immediately patch to a fixed version Atlassian recommends that you upgrade your instance to one of the versions listed in the “Fixed Versions” table section of this ticket. For full descriptions of the above versions of Jira Service Management Data Center, see the [release notes|https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html]. You can download the latest version of Jira Service Management Data Center from the [download center|https://www.atlassian.com/software/jira/service-management/download-archives]. h3. Apply temporary mitigations if unable to patch Remove your instance from the internet until you can patch or apply mitigations, if possible. Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action. h4. Option 1: Apply a Web Application Firewall Rule, requires regex filtering Apply a rule, described below, to your Web Application Firewall or proxy layer. Rule implementation instructions are dependent on your technology (e.g. reverse proxy, AWS WAF, or Cloudflare). # Block any URL containing this regex pattern {noformat} (?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).* {noformat} The intent of this regex is to block {{..}} immediately adjacent to /, \, or {{::}}. # Test that your rule blocks {{..}} immediately adjacent to \, /, or {{::}} and handles the URL-encoded patterns h4. Option 2: Block requests using Tomcat’s RewriteValve First, back up your instance. Then, for each node in your Data Center cluster: # Shut down the node # Enable Tomcat’s RewriteValve: ## Locate the server.xml file: ### On Jira/JSM: {{conf/server.xml}} ## Make a copy of this file as a backup ## Inside this file identify the {{<Context>}} element representing the application, the docBase attribute will be a path including the product name; in the standard setup this will be the only {{<Context>}} element ## Add the following line within that element if it is not already there: {{<Valve className="org.apache.catalina.valves.rewrite.RewriteValve" />}} # Install the configuration: ## Locate the {{WEB-INF}} directory: ### On Jira/JSM: {{atlassian-jira/WEB-INF}} ## Within the directory, check if the file {{rewrite.config}} exists ## If it exists: ### Make a copy of the existing {{rewrite.config}} file as a backup ### Append the existing file with the content of [^rewrite.config] ## If it does not exist: ### Put attached [^rewrite.config] file in the directory # Restart the node Note: These mitigation actions are limited and not a replacement for patching your instance; you must patch as soon as possible
EPSS 0.74% · 53.0th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Bamboo Data Center | |
| Atlassian | Jira Software Data Center | |
| Atlassian | Fisheye Data Center | |
| Atlassian | Confluence Data Center | |
| Atlassian | Crucible Data Center | |
| Atlassian | Crowd Data Center | |
| Atlassian | Bitbucket Data Center | |
| Atlassian | Jira Service Management Data Center | |
| Atlassian | Crowd Server |
Timeline
- Oct 5, 2026 CVE Published
- Oct 6, 2026 EPSS Score
- Oct 6, 2026 Coalition ESS Score
- Oct 6, 2026 VulnCheck XDB Entry
- Oct 6, 2026 VulnCheck XDB Entry
- Oct 7, 2026 VulnCheck KEV Exploitation
- Oct 7, 2026 VulnCheck XDB Entry