Arbitrary File Access in Fisheye

XMLWordPrintable

    • Type: Public Security Vulnerability
    • Resolution: Fixed
    • Priority: Highest
    • 4.9.15
    • Affects Version/s: 4.9.0, 4.9.14
    • Component/s: None
    • 9.3
    • Critical
    • CVE-2026-21589
    • Path Traversal (Arbitrary Read/Write)
    • Fisheye Data Center

      Summary of Vulnerability

      All Fisheye versions are affected by this vulnerability.

      This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be sensitive files present that increase your risk.

      Fisheye versions as listed below are at risk and require immediate attention. See ‘What You Need to Do’ for detailed instructions.

      This critical severity Arbitrary File Access vulnerability known as CVE-2026-21589 affects all versions prior to the listed fix versions of Fisheye. Versions outside of the support window (i.e. versions that have reached End of Life) may also be affected, so Atlassian recommends you upgrade to a fixed version.

      Affected Versions

      Product Affected Versions
      Fisheye All versions are affected

      Fixed Versions

      Product Fixed Versions
      Fisheye 4.9.15

       

      What You Need to Do

      Immediately patch to a fixed version

      Atlassian recommends that you upgrade your instance to one of the versions listed in the “Fixed Versions” table section of this ticket. For full descriptions of the above versions of Fisheye Data Center, see the release notes. You can download the latest version of Fisheye from the download center.

      Apply temporary mitigations if unable to patch

      Option 1: Apply a Web Application Firewall Rule, requires regex filtering

      Apply a rule, described below, to your Web Application Firewall or proxy layer. Rule implementation instructions are dependent on your technology (e.g. reverse proxy, AWS WAF, or Cloudflare).

      1. Block any URL containing this regex pattern
        (?is).*(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2})(?:\.|%(?:25)*2e){2}(?:/|\\|::|%(?:25)*(?:2f|5c)|(?::|%(?:25)*3a){2}|;|%(?:25)*3b|$).*
        

        The intent of this regex is to block .. immediately adjacent to /, \, or ::.

      2. Test that your rule blocks .. immediately adjacent to \, /, or :: and handles the URL-encoded patterns

      Note: These mitigation actions are limited and not a replacement for patching your instance; you must patch as soon as possible

              Assignee:
              Unassigned
              Reporter:
              Garima Katyal
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: