Atlassian Jira March 2026 Security Update Advisory

Atlassian Jira March 2026 Security Update Advisory

overview

Atlassian(https://www.atlassian.com/) has released a security update that addresses a vulnerability in a product it has shipped. users of affected products are encouraged to update to the latest version.

affected products

Bitbucket Data Center version 9.4.16

Bitbucket Data Center 10.1.1 version

Bitbucket Server version 9.4.16

Bitbucket Server 10.1.1 version

Confluence Data Center 8.5.0 version

Confluence Data Center 8.5.3 version

Confluence Data Center 8.6.0 version

Confluence Data Center 8.7.1 version

Confluence Data Center 8.8.0 version

Confluence Data Center 8.9.0 version

Confluence Data Center 9.0.1 version

Confluence Data Center 9.1.0 version

Confluence Data Center 9.2.0 version

Confluence Data Center 9.3.1 version

Confluence Data Center 9.4.0 version

Confluence Data Center 9.5.1 version

Confluence Data Center 10.0.2 version

Confluence Data Center 10.1.0 version

Confluence Data Center 10.2.0 version

Confluence Server 8.5.0 version

Confluence Server 8.5.3 version

Confluence Server 8.6.0 version

Confluence Server 8.7.1 version

Confluence Server 8.8.0 version

Confluence Server 8.9.0 versions

Confluence Server 9.0.1 version

Confluence Server 9.1.0 version

Confluence Server 9.2.0 version

Confluence Server 9.3.1 version

Confluence Server 9.4.0 version

Confluence Server 9.5.1 version

Confluence Server 10.0.2 version

Confluence Server 10.1.0 versions

Confluence Server 10.2.0 version

Crowd Data Center 5.3.1 version

Crowd Data Center 6.0.0 version

Crowd Data Center 6.1.0 version

Crowd Data Center 6.1.5 version

Crowd Data Center 6.2.0 版本

Crowd Data Center 6.2.4 版本

Crowd Data Center 6.3.0 版本

Crowd Data Center 7.0.0 Version

Crowd Data Center 7.1.0 Version

Crowd Data Center 7.1.0 and later versions 7.1.3 and earlier

Crowd Server 5.3.1 Versions

Crowd Server 6.0.0 Versions

Crowd Server 6.1.0 Versions

Crowd Server 6.1.5 Versions

Crowd Server 6.2.0 Versions

Crowd Server 6.2.4 版本

Crowd Server 6.3.0 版本

Crowd Server 7.0.0 Versions

Crowd Server 7.1.0 版本

Crowd Server 7.1.0 and later versions 7.1.3 and earlier

Jira Service Management Data Center 5.15.2 version

Jira Service Management Data Center 5.16.0 version

Jira Service Management Data Center 5.17.0 version

Jira Service Management Data Center 5.17.2 versions

Jira Service Management Data Center 10.0.0 version

Jira Service Management Data Center 10.1.1 version

Jira Service Management Data Center 10.2.0 version

Jira Service Management Data Center 10.3.0 version

Jira Service Management Data Center 10.3.0 and later and 10.3.1 and earlier versions

Jira Service Management Data Center 10.3.1 versions

Jira Service Management Data Center 10.3.1 and later but not earlier than 10.3.2

Jira Service Management Data Center 10.3.2 versions

Jira Service Management Data Center 10.3.2 and later but not earlier than 10.3.3

Jira Service Management Data Center 10.3.3 versions

Jira Service Management Data Center 10.3.3 and later versions 10.3.4 and earlier

Jira Service Management Data Center 10.3.4 versions

Jira Service Management Data Center 10.3.4 and later but not earlier than 10.3.5

Jira Service Management Data Center 10.3.5 versions

Jira Service Management Data Center 10.3.5 or later and 10.3.6 or earlier

Jira Service Management Data Center 10.3.6 versions

Jira Service Management Data Center 10.3.6 and later versions 10.3.7 and earlier

Jira Service Management Data Center 10.3.7 versions

Jira Service Management Data Center 10.3.7 and later versions 10.3.8 and earlier

Jira Service Management Data Center 10.3.8 versions

Jira Service Management Data Center 10.3.8 or later and 10.3.9 or earlier

Jira Service Management Data Center 10.3.9 versions

Jira Service Management Data Center 10.3.9 and later and 10.3.10 or earlier

Jira Service Management Data Center 10.3.10 versions

Jira Service Management Data Center 10.3.10 and later versions 10.3.11 and earlier

Jira Service Management Data Center 10.3.11 versions

Jira Service Management Data Center 10.3.11 and later versions 10.3.12 and earlier

Jira Service Management Data Center 10.3.12 versions

Jira Service Management Data Center 10.3.12 or later and 10.3.13 or earlier

Jira Service Management Data Center 10.3.13 versions

Jira Service Management Data Center 10.3.13 or later and 10.3.14 or earlier

Jira Service Management Data Center 10.3.14 versions

Jira Service Management Data Center 10.3.14 and later versions 10.3.15 and earlier

Jira Service Management Data Center 10.3.15 versions

Jira Service Management Data Center 10.3.15 and later versions 10.3.16 and earlier

Jira Service Management Data Center 10.3.16 versions

Jira Service Management Data Center 10.3.16 and later versions 10.3.17 and earlier

Jira Service Management Data Center 10.3.17 versions

Jira Service Management Data Center 10.4.0 versions

Jira Service Management Data Center 10.5.0 versions

Jira Service Management Data Center 10.6.0 version

Jira Service Management Data Center 10.7.1 version

Jira Service Management Data Center 11.0.0 version

Jira Service Management Data Center 11.1.0 version

Jira Service Management Data Center 11.2.0 version

Jira Service Management Data Center 11.3.0 version

Jira Service Management Data Center 11.3.0 and later versions and 11.3.1 and earlier versions

Jira Service Management Data Center 11.3.1 versions

Jira Service Management Data Center 11.3.1 and later but not earlier than 11.3.2

Jira Service Management Data Center 11.3.2 versions

Jira Service Management Server 5.17.2 version

Jira Service Management Server 10.0.0 version

Jira Service Management Server 10.1.1 version

Jira Service Management Server 10.2.0 version

Jira Service Management Server 10.3.0 or later and 10.3.16 or earlier

Jira Service Management Server 10.4.0 versions

Jira Service Management Server 10.5.0 versions

Jira Service Management Server 10.6.0 versions

Jira Service Management Server 10.7.1 version

Jira Service Management Server 11.0.0 version

Jira Software Data Center 9.15.2 version

Jira Software Data Center 9.16.0 version

Jira Software Data Center 9.17.0 version

Jira Software Data Center 9.17.2 version

Jira Software Data Center 10.0.0 version

Jira Software Data Center 10.1.1 version

Jira Software Data Center 10.2.0 version

Jira Software Data Center 10.3.0 version

Jira Software Data Center 10.3.0 and later and 10.3.1 and earlier versions

Jira Software Data Center 10.3.1 versions

Jira Software Data Center 10.3.1 and later versions 10.3.2 and earlier

Jira Software Data Center 10.3.2 versions

Jira Software Data Center 10.3.2 or later and 10.3.3 or earlier

Jira Software Data Center 10.3.3 versions

Jira Software Data Center 10.3.3 and later versions 10.3.4 and earlier

Jira Software Data Center 10.3.4 versions

Jira Software Data Center 10.3.4 and later versions 10.3.5 and earlier

Jira Software Data Center 10.3.5 versions

Jira Software Data Center 10.3.5 or later and 10.3.6 or earlier

Jira Software Data Center 10.3.6 versions

Jira Software Data Center 10.3.6 and later versions 10.3.7 and earlier

Jira Software Data Center 10.3.7 versions

Jira Software Data Center 10.3.7 and later versions 10.3.8 and earlier

Jira Software Data Center 10.3.8 versions

Jira Software Data Center 10.3.8 or later and 10.3.9 or earlier

Jira Software Data Center 10.3.9 versions

Jira Software Data Center 10.3.9 or later and 10.3.10 or earlier

Jira Software Data Center 10.3.10 versions

Jira Software Data Center 10.3.10 and later versions 10.3.11 and earlier

Jira Software Data Center 10.3.11 versions

Jira Software Data Center 10.3.11 and later versions 10.3.12 and earlier

Jira Software Data Center 10.3.12 versions

Jira Software Data Center 10.3.12 or later and 10.3.13 or earlier

Jira Software Data Center 10.3.13 versions

Jira Software Data Center 10.3.13 or later and 10.3.16 or earlier

Jira Software Data Center 10.4.0 versions

Jira Software Data Center 10.5.0 versions

Jira Software Data Center 10.6.0 versions

Jira Software Data Center 10.7.1 version

Jira Software Data Center 11.0.0 version

Jira Software Data Center 11.1.0 version

Jira Software Data Center 11.2.0 version

Jira Software Data Center 11.3.0 and later and 11.3.1 and earlier versions

Jira Software Data Center 11.3.1 versions

Jira Software Data Center 11.3.1 and later versions 11.3.2 and earlier

Jira Software Data Center 11.3.2 versions

Jira Software Server 9.17.2 version

Jira Software Server 10.0.0 version

Jira Software Server 10.1.1 version

Jira Software Server 10.2.0 version

Jira Software Server 10.3.0 or later and 10.3.16 or earlier

Jira Software Server 10.4.0 versions

Jira Software Server 10.5.0 versions

Jira Software Server 10.6.0 versions

Jira Software Server 10.7.1 version

Jira Software Server 11.0.0 version

Jira Software Server 11.3.0 and later 11.3.1 and earlier versions

resolved vulnerabilities

Vulnerability in Jira Software Data Center that allows for a path traversal attack (CVE-2026-23950, CVSS 8.8) [1]

File-included node-tar dependency vulnerability in Jira Software Data Center (CVE-2026-24842, CVSS 8.2) [2] [3

File-included node-tar dependency vulnerability in Jira Software Data Center (CVE-2026-23745, CVSS 8.2) [3] [4

Vulnerability in Jira Software Data Center that allows denial of service attacks (CVE-2020-28469, CVSS 7.5) [4]

A possible denial of service attack in Jira Software Data Center/Server (CVE-2022-25883, CVSS 7.5) [5]

Vulnerability in Jira Software Data Center/Server that allows for a denial of service attack (CVE-2022-25927, CVSS 7.5) [6] [7

vulnerability patches

Please follow the security advisory published on March 17 to update to these and the latest version.

Bitbucket Data Center version 9.4.17

Bitbucket Data Center 10.1.5 version

Bitbucket Data Center 10.2.0 version

Bitbucket Server version 9.4.17

Bitbucket Server 10.1.5 version

Bitbucket Server 10.2.0 version

Confluence Data Center 9.2.1 version

Confluence Data Center 9.2.13 or later to 9.2.15 or earlier

Confluence Data Center 9.4.0 versions

Confluence Data Center 9.5.1 versions

Confluence Data Center 10.2.2 or later and 10.2.3 or earlier

Confluence Data Center 10.2.3 versions

Confluence Data Center 10.2.6 version

Confluence Server 9.2.1 version

Confluence Server 9.2.13 or later and 9.2.15 or earlier

Confluence Server 9.4.0 versions

Confluence Server 9.5.1 versions

Confluence Server 10.2.2 or later and 10.2.3 or earlier

Confluence Server 10.2.3 versions

Confluence Server 10.2.6 versions

Crowd Data Center 6.3.5 version

Crowd Data Center 7.1.5 version

Crowd Server 6.3.5 version

Crowd Server 7.1.5 version

Jira Service Management Data Center 10.3.17 or later and 10.3.18 or earlier

Jira Service Management Data Center 10.3.18 version

Jira Service Management Data Center 11.3.0 version

Jira Service Management Data Center 11.3.0 and later versions and 11.3.1 and earlier versions

Jira Service Management Data Center 11.3.3 versions

Jira Service Management Server 10.3.17 version

Jira Service Management Server 11.3.0 version

Jira Software Data Center 10.3.17 or later and 10.3.18 or earlier

Jira Software Data Center 10.3.18 versions

Jira Software Data Center 11.3.0 version

Jira Software Data Center 11.3.2 and later versions and 11.3.3 and earlier versions

Jira Software Data Center 11.3.3 versions

Jira Software Server 10.3.17 version

Jira Software Server 11.3.0 versions

Jira Software Server 11.3.2 versions

reference sites

[1] Path Traversal node-tar Dependency in Jira Software Data Center

https://jira.atlassian.com/browse/JSWSERVER-26736

[2] File Inclusion node-tar Dependency in Jira Software Data Center

https://jira.atlassian.com/browse/JSWSERVER-26733

[3] File Inclusion node-tar Dependency in Jira Software Data Center

https://jira.atlassian.com/browse/JSWSERVER-26732

[4] DoS (Denial of Service) glob-parent Dependency in Jira Software Data Center

https://jira.atlassian.com/browse/JSWSERVER-26730

[5] DoS (Denial of Service) semver Dependency in Jira Software Data Center and Server

https://jira.atlassian.com/browse/JSWSERVER-26716

[6] DoS (Denial of Service) ua-parser-js Dependency in Jira Software Data Center

https://jira.atlassian.com/browse/JSWSERVER-26714

[7] Atlassian Security Advisories & Bulletins

https://www.atlassian.com/trust/security/advisories