
Threat actors have started exploiting CVE-2026-21589 (CVSS score of 9.3), a critical arbitrary file access flaw in Atlassian Data Center products. The vulnerability could allow attackers to access sensitive files under certain conditions. Affected products include Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye.
“This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file’s exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents.” reads the advisory. “In some configurations, there may be some sensitive files that make this highly severe.”
Previdian telemetry has detected 15 exploitation attempts from three IP addresses in Japan and the U.S..
On October 6, watchTowr Labs published a technical analysis of CVE-2026-21589 after comparing vulnerable and patched Atlassian packages.
Researchers found a path traversal flaw where double-colon (::) sequences can be treated as path separators, allowing attackers to read files from the application web root.
“While semicolons (;) are very common in path traversal within Java applications, along with the everyday dots (.) and slashes (/), one item stood out: the matching of double colons (::).” reads the analysis. “This is uncommon syntax for this type of vulnerability, but grepping through the codebase we came across an all too familiar sight.”
In one Crowd deployment with Jira, researchers were able to read crowd.properties, which exposed application credentials. They then used those credentials to create a user and add it to the jira-administrators group. Crowd IP allowlisting can block this attack path.
Exploitation attempts against watchTowr’s honeypot network reportedly started about two hours after watchTowr published the analysis of the vulnerability.
Previdian also confirmed active exploitation of the issue.
“Exploitation has now started to hit our honeypot network” Previdian Founder Ryan Dewhurst wrote on LinkedIn.
The flaw allows unauthenticated attackers to read sensitive files in the webroot with a single request. This could expose tokens, credentials, keys, and other authentication data.
The exploitation activity targeting its honeypot network is said to have begun two hours after watchTowr released additional technical details of the vulnerability.
According to watchTowr, the problem is in Atlassian’s web-resource handling. It can turn a string such as ..::..::..::..::WEB-INF::web.xml into ../../../../WEB-INF/web.xml, allowing attackers to move through directories and access files they should not be able to read.
Atlassian says all versions before the listed fixed versions are affected:
| Product | Fixed versions |
|---|---|
| Bitbucket Data Center | 9.4.26, 10.2.8, 10.5.1 |
| Confluence Data Center | 9.2.26, 10.2.19 |
| Jira Service Management Data Center | 5.12.40, 10.3.26, 11.3.12 |
| Jira Software Data Center | 9.12.40, 10.3.26, 11.3.12 |
| Bamboo Data Center | 10.2.24, 12.1.12 |
| Crowd Data Center | 6.3.7, 7.0.3, 7.1.7, 7.2.4 |
| Crucible | 4.9.15 |
| Fisheye | 4.9.15 |
As a temporary measure, Atlassian recommends removing affected instances from the public internet. Customers can also use a Web Application Firewall (WAF) rule to block malicious requests.
For Confluence, JSM, Jira, Bamboo, and Crowd, customers can block the requests using Tomcat’s RewriteValve. Bitbucket users can add a new rule to the urlrewrite.xml file.
watchTowr has released a free tool on GitHub to help check if a server is vulnerable.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Atlassian)