Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589)
Attackers are probing Atlassian Data Center products for critical file-read flaw CVE-2026-21589 one day after patches.
One day after Atlassian patched CVE-2026-21589, a critical arbitrary file-access flaw in self-managed Data Center products, Previdian reported exploitation attempts against its honeypots. watchTowr traced the bug to atlassian-plugins-webresource, where double colons are converted to slashes and bypass path filters, allowing reads of files such as WEB-INF/web.xml. On Crowd, crowd.properties can expose plaintext application credentials that let an attacker list users, create accounts, and add them to groups such as jira-administrators. Affected products include Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye; Atlassian urges upgrades or isolating instances from the internet.
- CVE-2026-21589 allows arbitrary file reads in Atlassian Data Center products.
- Double-colon path traversal bypasses slash-stripping in a shared webresource library.
- Crowd crowd.properties can leak plaintext credentials usable for admin account creation.
- Previdian saw exploitation attempts on honeypots hours after watchTowr's write-up.
- Atlassian urges immediate upgrades or taking instances off the internet.
Vulnerabilities mentionedAll →
- CVE-2026-215899.32%This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access…published PoC ×7
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21589 | This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access… |
Full article468 words · extracted from helpnetsecurity.com · click to collapse
One day after Atlassian released patches fixing a critical arbitrary file access vulnerability (CVE-2026-21589) in its self-managed Data Center products, and a few hours after watchTowr researchers published a technical rundown of the flaw, attackers have been spotted attempting to exploit it.

CVE-2026-21589 PoC in action (Source: watchTowr)
“Exploitation attempts have now started to hit our honeypot network,” threat intelligence vendor Previdian warned late Tuesday, and shared a list of attacker IPs.
About CVE-2026-21589
CVE-2026-21589 affects all versions of Atlassian’s Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.
Successful exploitation may allow attackers to access specific files within the web application root directory of vulnerable instances.
“In some configurations, there may be sensitive files present that increase your risk,” Atlassian said, but added that “exploitation requires prior knowledge of the target file’s exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents.”
CVE-2026-21589: The technical details
Offensive security firm watchTowr dug into the fixes to pinpoint the cause of CVE-2026-21589, and traced it to atlassian-plugins-webresource*.jar, a library shared by the vulnerable solutions.
By comparing the vulnerable JAR and the patched one, watchTowr found a quirk in the routing code: functions that convert double colons (::) into forward slashes (/). That lets an attacker smuggle a path-traversal payload shaped like ..::..::..::<dir>::file.txt through a resource-serving route whose slash-stripping defenses are effectively bypassed.
Using a color-picker plugin route in Jira, they read the normally protected WEB-INF/web.xml, and showed equivalent routes for Confluence and Bitbucket. Effectively, they were able to read any file within the application server.
File read alone didn’t seem to justify a critical rating, so they followed the advisory’s hint that some configurations hold sensitive files.
They found that Atlassian Crowd deployments store crowd.properties under WEB-INF/classes, containing the application name and password in plaintext.
With those leaked credentials, an attacker can “talk” directly to Crowd, Atlassian’s identity and SSO hub, to list users, create new accounts, and add them to groups like jira-administrators, effectively becoming a Jira admin.
watchTowr created (but did not publish) a PoC exploit, and provided a script that can be used to check whether a target Jira, Confluence or BitBucket instance is vulnerable to CVE-2026-21589.
Atlassian urged customers to upgrade to a fixed version as soon as possible.
Those who can’t do it quickly have been advised to remove their vulnerable instances from the internet until they can, or block access to it from external networks.
Finally, Atlassian advised customers to check for evidence of compromise by analyzing access-log request lines for specific indicators.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
