Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)
Attackers are scanning Atlassian products for CVE-2026-21589, a traversal bug that can read web files.
On October 5, Atlassian patched CVE-2026-21589, an arbitrary file-access flaw in which slash characters encoded as "::" can be turned back into a directory traversal. Access is limited to the web application directory; proof-of-concept requests target files such as WEB-INF/web.xml on Jira, Bitbucket, and Confluence. The SANS Internet Storm Center said honeypots received matching exploit attempts starting October 6 using URLs from a Watchtowr write-up. Every observed source address was hosted at DigitalOcean, which the author believes indicates a single actor.
- CVE-2026-21589 allows arbitrary file reads inside Atlassian web directories.
- Watchtowr published proof-of-concept requests for Jira, Bitbucket, and Confluence.
- SANS honeypots saw matching exploit attempts starting October 6.
- Observed source addresses were all hosted at DigitalOcean.
Vulnerabilities mentionedAll →
- CVE-2026-215899.32%This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access…published PoC ×7
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21589 | This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access… |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 134.199.229.190 | ith Digital Ocean. The source IPs I see from our honeypots: 134.199.229.190 134.199.230.82 137.184.112.247 137.184.33.84 143.198.103.58 |
| ipv4 | 134.199.230.82 | n. The source IPs I see from our honeypots: 134.199.229.190 134.199.230.82 137.184.112.247 137.184.33.84 143.198.103.58 143.198.132.93 |
| ipv4 | 137.184.112.247 | Ps I see from our honeypots: 134.199.229.190 134.199.230.82 137.184.112.247 137.184.33.84 143.198.103.58 143.198.132.93 146.190.169.1 1 |
| ipv4 | 137.184.33.84 | r honeypots: 134.199.229.190 134.199.230.82 137.184.112.247 137.184.33.84 143.198.103.58 143.198.132.93 146.190.169.1 146.190.172.250 |
| ipv4 | 143.198.103.58 | 34.199.229.190 134.199.230.82 137.184.112.247 137.184.33.84 143.198.103.58 143.198.132.93 146.190.169.1 146.190.172.250 159.223.199.21 |
| ipv4 | 143.198.132.93 | 134.199.230.82 137.184.112.247 137.184.33.84 143.198.103.58 143.198.132.93 146.190.169.1 146.190.172.250 159.223.199.218 164.92.68.152 |
| ipv4 |
Full article263 words · extracted from isc.sans.edu · click to collapse
On October 5th, Atlassian published patches for multiple products to fix an "Arbitrary File Access" vulnerability [CVE-2026-21589]. An attacker can read arbitrary files in the web application's directory, potentially exposing sensitive information such as configuration files.
This directory traversal vulnerability is a little bit different from the textbook case. Atlassian products replace slashes with the pattern "::". To avoid this issue, but may, in some cases, undo this escape to access files. Watchtowr has a great write-up with all the details and proof-of-concept URLs demonstrating the vulnerability [Watchtowr].
Starting yesterday, we saw some exploit attempts hitting our honeypot, using the exploit URLs mentioned in the Watchtowr blog.
/download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml
/s/1.0/_/download/resources/com.atlassian.bitbucket.server.bitbucket-webpack-INTERNAL:avatar/avatar/..::..::..::..::..::WEB-INF::urlrewrite.xml
/s/1/_/download/resources/com.atlassian.confluence.plugins.dashboard-actions/images/..::..::..::..::..::..::..::..::WEB-INF::web.xml
One condition for successful exploitation is that the file the user attempts to access exists. The exploit uses "WEB-INF/web.xml" as it is a required file for Tomcat applications, and can be used similarly to "/etc/passwd". The "/etc/passwd" file will not work in this case. Access is restricted to the web application's directory. The "::" pattern used in the exploit will be translated to "/" on the server, leading to the directory traversal.
Based on the timing and the targets hit, I believe these scans are all triggered by the same threat actor. Oddly enough, all the source IPs are associated with Digital Ocean. The source IPs I see from our honeypots:
134.199.229.190
134.199.230.82
137.184.112.247
137.184.33.84
143.198.103.58
143.198.132.93
146.190.169.1
146.190.172.250
159.223.199.218
164.92.68.152
209.38.147.216
24.199.101.184
64.23.172.129
--
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|
Text extracted automatically; images, tables and formatting may be missing. Original: