Critical Flaw in Multiple Atlassian Products Exploited in the Wild
Unauthenticated Atlassian flaw CVE-2026-21589 is exploited in the wild to read Data Center application files.
Atlassian disclosed CVE-2026-21589, a CVSS 9.3 unauthenticated arbitrary file-read flaw affecting eight self-managed Data Center products, including Jira, Confluence, Bitbucket, Bamboo, and Crowd. WatchTowr traced it to path-handling in the shared atlassian-plugins-webresource library, which can expose webroot files such as crowd.properties and the credentials used to reach Crowd, potentially enabling user or privilege changes. On October 7, VulnCheck added the flaw to its known-exploited list after activity targeting Bamboo Data Center; it was not in CISA’s KEV catalog at publication. Atlassian listed fixed versions and temporary WAF or rewrite mitigations and said it cannot confirm whether instances were compromised.