Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
Unauthenticated Atlassian Data Center flaw CVE-2026-21589 saw exploitation attempts within two hours.
Atlassian disclosed CVE-2026-21589, a CVSS 9.3 unauthenticated arbitrary file-access flaw in Data Center editions of Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye. An attacker who already knows an exact path can read files under the web root; on Crowd and Jira that can include crowd.properties and lead to administrative access. Previdian reported 15 honeypot attempts from three IP addresses in Japan and the United States, starting about two hours after watchTowr published technical details. Atlassian says Cloud is patched, fixed Data Center builds are available, and temporary options include removing instances from the internet or applying WAF and rewrite rules.
- CVE-2026-21589 is a CVSS 9.3 unauthenticated file-access flaw.
- It affects Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye.
- Previdian logged 15 honeypot attempts from three IPs within two hours.
- Reading crowd.properties can expose credentials and enable admin access.
- Patches are available; isolation and WAF rules are temporary mitigations.
Vulnerabilities mentionedAll →
- CVE-2026-215899.32%This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access…published PoC ×7
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21589 | This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access… |
Full article558 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 07, 2026Vulnerability / Web Security
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions.
The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye.
"This arbitrary file access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions," the Australian company said.
"Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be sensitive files present that increase your risk."
Atlassian said impacted Atlassian Cloud products have been patched, adding that fixes are available for the following products -
- Bitbucket Data Center - 9.4.26, 10.2.8, and 10.5.1
- Confluence Data Center - 9.2.26 and 10.2.19
- Jira Service Management Data Center - 5.12.40, 10.3.26, and 11.3.12
- Jira Software Data Center - 9.12.40, 10.3.26, and 11.3.12
- Bamboo Data Center - 10.2.24 and 12.1.12
- Crowd Data Center - 6.3.7, 7.0.3, 7.1.7, and 7.2.4
- Crucible - 4.9.15
- Fisheye - 4.9.15
As temporary mitigation, Atlassian is recommending that customers remove their instance from the public internet, apply a Web Application Firewall (WAF) rule, block requests using Tomcat's RewriteValve (for Confluence, JSM, Jira, Bamboo, and Crowd), and add a new rule to urlrewrite.xml (for Bitbucket).
According to telemetry data from Previdian, a total of 15 exploitation attempts have been detected from three unique IP addresses located in Japan and the U.S. -
- 38.60.157[.]86
- 146.70.187[.]234
- 159.26.119[.]225
The exploitation activity targeting its honeypot network is said to have begun two hours after watchTowr released additional technical details of the vulnerability, stating it allows unauthenticated attackers to retrieve sensitive files within the webroot directory through a single request and extract tokens, credentials, keys, or other authentication material.
According to the preemptive exposure management firm, the underlying vulnerability has to do with Atlassian's web-resource handling, which converts a string like "..::..::..::..::WEB-INF::web.xml" to "../../../../WEB-INF/web.xml."
As a result, an unauthenticated attacker with knowledge of the resource-resolution logic can abuse this path resolution logic and combine it with an Atlassian "/includes/jquery/plugins/colorpicker/images/" plugin resource by taking advantage of the trailing "/" to reach other files (e.g., "WEB-INF/web.xml") elsewhere in the application -
GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml HTTP/1.1
Host: {{Jira-Hostname}}
Importantly, in the case of Atlassian Crowd and Jira, the attacker could exploit the flaw to access "WEB-INF/classes/crowd.properties," which stores Crowd credentials, and then use them to gain administrative access to the application. Armed with this privileged access, it's possible to create new users, modify user privileges, and elevate a newly created rogue user to Jira Administrator.
"Within two hours of public exploit details becoming available, we were already seeing exploitation attempts hit our honeypot network," Previdian Founder and CEO Ryan Dewhurst said in a statement shared with The Hacker News.
"The release of a Nuclei template will make mass automated scanning even easier, so we expect activity around CVE-2026-21589 to increase quickly. Organizations running affected Atlassian products should treat patching as an immediate priority."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.