-
Type:
Public Security Vulnerability
-
Resolution: Fixed
-
Priority:
Highest
-
Affects Version/s: 10.5.0, 9.4.24, 10.2.7
-
Component/s: None
-
9.3
-
Critical
-
CVE-2026-21589
-
Bitbucket Data Center
Summary of Vulnerability
All Bitbucket Data Center versions are affected by this vulnerability.
This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be sensitive files present that increase your risk.
Bitbucket Data Center versions as listed below are at risk and require immediate attention. See ‘What You Need to Do’ for detailed instructions.
Bitbucket Cloud site is not affected by this vulnerability.
This critical severity Arbitrary File Access vulnerability known as CVE-2026-21589 affects all versions prior to the listed fix versions of Bitbucket Data Center. Versions outside of the support window (i.e. versions that have reached End of Life) may also be affected, so Atlassian recommends you upgrade to a fixed LTS version or later.
Affected Versions
| Product | Affected Versions |
|---|---|
| Bitbucket Data Center | All versions are affected |
Fixed Versions
| Product | Fixed Versions |
|---|---|
| Bitbucket Data Center |
|
What You Need to Do
Immediately patch to a fixed version
Atlassian recommends that you upgrade your instance to one of the versions listed in the “Fixed Versions” table section of this ticket. For full descriptions of the above versions of Bitbucket Data Center, see the release notes. You can download the latest version of Bitbucket Data Center from the download center.
Apply temporary mitigations if unable to patch
Remove your instance from the internet until you can patch or apply mitigations, if possible. Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action.
Option 1: Apply a Web Application Firewall Rule, requires regex filtering
Apply a rule, described below, to your Web Application Firewall or proxy layer. Rule implementation instructions are dependent on your technology (e.g. reverse proxy, AWS WAF, or Cloudflare).
- Block any URL containing this regex pattern
(?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).*The intent of this regex is to block .. immediately adjacent to /, \, or ::.
- Test that your rule blocks .. immediately adjacent to \, /, or :: and handles the URL-encoded patterns
Option 2: Add rule to urlrewrite.xml
For a clustered system, this patch should be applied to all nodes. Similarly, apply the patch to all Bitbucket mirrors and Bitbucket mirror farm nodes.
- First, back up your instance. (see Data recovery and backups)
- Edit the <installation-directory>/app/WEB-INF/urlrewrite.xml file
- Add a new <rule> to the top of the file, before other <rule>s
<rule> <from>(?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).*</from> <set type="status">404</set> <to>/mvc/error404</to> </rule>
When the mitigation is applied, the top of the urlrewrite.xml file should look like the below:
<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE urlrewrite PUBLIC "-//tuckey.org//DTD UrlRewrite 4.0//EN" "dtds/urlrewrite4.0.dtd"><urlrewrite decode-using="utf8"> <rule> <from>(?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).*</from> <set type="status">404</set> <to>/mvc/error404</to> </rule> <!-- Johnson Error Pages --> <rule> [...]
- Restart Bitbucket Data Center
Note: These mitigation actions are limited and not a replacement for upgrading your instance; you must upgrade as soon as possible