Critical Flaw in Multiple Atlassian Products Exploited in the Wild
Unauthenticated Atlassian flaw CVE-2026-21589 is exploited in the wild to read Data Center application files.
Atlassian disclosed CVE-2026-21589, a CVSS 9.3 unauthenticated arbitrary file-read flaw affecting eight self-managed Data Center products, including Jira, Confluence, Bitbucket, Bamboo, and Crowd. WatchTowr traced it to path-handling in the shared atlassian-plugins-webresource library, which can expose webroot files such as crowd.properties and the credentials used to reach Crowd, potentially enabling user or privilege changes. On October 7, VulnCheck added the flaw to its known-exploited list after activity targeting Bamboo Data Center; it was not in CISA’s KEV catalog at publication. Atlassian listed fixed versions and temporary WAF or rewrite mitigations and said it cannot confirm whether instances were compromised.
- CVE-2026-21589 is a CVSS 9.3 unauthenticated file read across eight Atlassian Data Center products.
- Shared web-resource library allows path-traversal bypass and webroot file access.
- Stolen crowd.properties credentials could let attackers alter Crowd users and privileges.
- VulnCheck reports exploitation against Bamboo; CISA KEV has not listed it.
- Atlassian published fixed versions plus temporary WAF and rewrite mitigations.
Vulnerabilities mentionedAll →
- CVE-2026-215899.32%This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access…published PoC ×7
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21589 | This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access… |
Full article756 words · extracted from infosecurity-magazine.com · click to collapse
A critical vulnerability in Atlassian Data Center products is reportedly being exploited in the wild.
The flaw, tracked as CVE-2026-21589, was described by Atlassian in an October 5 advisory as an arbitrary file access, with a severity score (CVSS) of 9.3.
It affects eight Atlassian products, widely used in enterprise IT systems:
- Bitbucket Data Center: a Git-based source-code management and collaboration for software development teams, used to host repositories, manage code changes and pull requests
- Confluence Data Center: a team collaboration and knowledge-management platform, used for documentation, internal wikis, project information and shared knowledge
- Jira Service Management Data Center: an IT service-management (ITSM) platform, used for service desks, incident management, service requests, changes and other IT workflows
- Jira Software Data Center: a project and software-development management platform, used to plan, track and manage software work, including issues, sprints and releases
- Bamboo Data Center: a continuous integration/continuous delivery (CI/CD) server used to automate software builds, tests and deployments
- Crowd Data Center: a centralized identity and user-management platform for Atlassian and other applications, providing capabilities such as authentication and user-directory management
- Crucible: a collaborative code-review tool, allowing developers to review and discuss changes to source code
- Fisheye: a source-code repository browser and analysis tool, providing visibility into code repositories and development activity
The “data center” products are self-managed versions of Atlassian products, where the customer runs the software and manages the underlying infrastructure, rather than Atlassian hosting and operating it as software-as-service (SaaS). They typically are hosted in the company’s own data center or on infrastructure it controls in a public cloud such as AWS or Azure.
Exploiting CVE-2026-21589 allows an attacker with no login access to read specific files in each product's web application root directory.
Evidence of CVE-2026-21589 Exploitation Targeting Bamboo Data Center
In a vulnerability analysis published on October 6, WatchTowr found that the affected Atlassian products share a common Atlassian Web Resource framework, specifically the atlassian-plugins-webresource library. This shared library contains the vulnerable path-handling logic that allows an attacker to bypass path-traversal protections and read files from the application's webroot.
This explains why CVE-2026-21589 affects seemingly different products: they incorporate common Atlassian platform components, including this Web Resource library.
WatchTowr added that while Atlassian Crowd is also more than just one of the affected products, it plays an important role in the potential attack chain because it can be used as a central identity and authentication service for other Atlassian products. For example, when Jira is configured to use Crowd, Jira's crowd.properties configuration file contains the credentials that Jira uses to communicate with Crowd.
WatchTowr demonstrated that the arbitrary file-read vulnerability can be used to retrieve this file and expose those credentials.
This means the vulnerability can potentially go beyond simply reading files: an unauthenticated attacker could exploit CVE-2026-21589 to obtain Crowd credentials from an integrated Atlassian application and then use those credentials to interact with Crowd, potentially creating or modifying users and privileges.
In WatchTowr's demonstration, this provided a path towards obtaining Jira administrator-level access.
On October 7, VulnCheck added CVE-2026-21589 to its known exploited vulnerabilities (KEV) list, observing exploitation activity targeting Bamboo Data Center. VulnCheck’s dashboard links to Previdian as a source of exploitation intelligence.
The vulnerability has not been added to the US Cybersecurity and Infrastructure Securiy’s (CISA) own KEV catalog at the time of writing.
Atlassian’s Patch and Mitigation Recommendations
In its advisory, Atlassian provides the list of patched versions for each of the eight products affected by CVE-2026-21589:
- Bitbucket Data Center (9.4.26, 10.2.8 and 10.5.1)
- Confluence Data Center (9.2.26 and 10.2.19)
- Jira Service Management Data Center (5.12.40, 10.3.26 and 11.3.12)
- Jira Software Data Center (9.12.40, 10.3.26 and 11.3.12)
- Bamboo Data Center (10.2.24 and 12.1.12)
- Crowd Data Center (6.3.7, 7.0.3, 7.1.7 and 7.2.4)
- Crucible (4.9.15)
- Fisheye (4.9.15)
Customers are urged to patch each of their affected installations to fixed versions or the latest version.
If they cannot patch, Atlassian also recommended temporary mitigations that include:
- Applying a web application firewall (WAF) rule (for all affected products)
- Blocking requests using Tomcat’s RewriteValve (for Confluence, JSM, Jira, Bamboo and Crowd)
- Adding a rule to urlrewrite.xml (for Bitbucket only)
Atlassian said it cannot confirm to users whether their instances have been affected by this vulnerability and recommended that customers engage with their local security team to check all affected instances for evidence of compromise.
WatchTowr has released a detection artefact generator for Jira, Confluence and Bitbucket that Atlassian customers can use to check whether an instance of any of these three product ranges is vulnerable.
Image credits: Fanta Media / bluestork / Shutterstock.com