PoC Exploit Released for Critical Atlassian Flaw That Can Lead to Jira Admin Access
watchTowr released a detection PoC for unauthenticated Atlassian file-read CVE-2026-21589 that can yield Jira admin access.
watchTowr published a detection proof of concept for CVE-2026-21589, a critical unauthenticated arbitrary file-read flaw in multiple self-managed Atlassian Data Center products. Shared web-resource handling converts double colons into slashes, enabling directory traversal to files under the application webroot, including WEB-INF. If Jira is integrated with Crowd, crowd.properties can expose application credentials that may allow creation of a jira-administrators account. Atlassian issued fixes on October 5, including Jira Software 9.12.40, 10.3.26, and 11.3.12; in-the-wild exploitation is not reported.
- CVE-2026-21589 is an unauthenticated arbitrary file read in shared Atlassian components.
- It affects Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye.
- Reading Crowd properties can expose credentials used to create Jira administrators.
- watchTowr released a detection PoC that sends safe requests only.
- Fixed builds include Jira Software 9.12.40, 10.3.26, and 11.3.12.
Vulnerabilities mentionedAll →
- CVE-2026-215899.32%This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access…published PoC ×7
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21589 | This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access… |
Full article584 words · extracted from cybersecuritynews.com · click to collapse
A proof-of-concept exploit has been released for CVE-2026-21589, a critical arbitrary file-read vulnerability affecting multiple self-managed Atlassian products. The flaw can expose sensitive application files and, in environments integrated with Atlassian Crowd, potentially allow attackers to obtain Jira administrator access.
Atlassian issued an out-of-band advisory on October 5. The vulnerability affects numerous Data Center products, including Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye. The weakness is particularly serious because the reported attack scenario shows it can be exploited remotely without authentication.
watchTowr labs published technical details and a detection proof of concept for Jira, Confluence, and Bitbucket. The released tool identifies vulnerable instances by sending safe detection requests rather than creating users or modifying target systems.
The issue exists in Atlassian’s shared web-resource handling component. Researchers found that affected products convert double colons into forward slashes during request processing. This behavior may let an attacker bypass path validation controls and perform directory traversal using specially constructed paths.
PoC Exploit Released for Critical Atlassian Flaw
The flaw enables access to files inside the application server’s webroot, including files in the normally protected WEB-INF directory. While the researchers at watchTowr Labs reported that the vulnerability does not necessarily permit reads outside the Tomcat application context, files within the application can still contain valuable configuration data, tokens, and service credentials.

For Jira, researchers demonstrated access to the application’s web.xml file through a crafted request to a downloadable resource path. Similar paths were identified for Confluence and Bitbucket, indicating that the underlying vulnerable component is shared across the product ecosystem.
The impact becomes far more severe when Jira is integrated with Atlassian Crowd, the company’s centralized identity and single sign-on platform. In certain configurations, Crowd connection settings are stored in a file named crowd.properties under WEB-INF/classes.
That file can contain the Crowd application name, application password, and Crowd server URL. If an attacker retrieves these credentials through CVE-2026-21589 and can reach the Crowd service, they may be able to authenticate to Crowd’s management interfaces.
Researchers said this access could enable an attacker to enumerate users, create a new account, and add it to the jira-administrators group. The result would be persistent administrator-level access to Jira without exploiting Jira’s authentication mechanism directly.
The attack chain depends on configuration. Crowd deployments that restrict access using IP allowlists may make direct exploitation harder. However, organizations with permissive internal network access or exposed identity services face a greater risk.

Atlassian released fixes for affected products. Patched versions include Jira Software Data Center 9.12.40, 10.3.26, and 11.3.12; Jira Service Management Data Center 5.12.40, 10.3.26, and 11.3.12; Confluence Data Center 9.2.26 and 10.2.19; and Bitbucket Data Center 9.4.26, 10.2.8, and 10.5.1. Fixes are also available for Bamboo, Crowd, Crucible, and Fisheye.
Administrators should immediately upgrade to a fixed release, restrict public access to Atlassian Data Center applications, review web and application logs for unusual resource-download requests, and rotate Crowd application passwords if affected systems may have been exposed.
Organizations should also inspect Crowd administrator memberships and newly created accounts for signs of compromise. watchTowr’s released detection artifact generator supports Jira, Confluence, and Bitbucket and can help defenders determine whether an instance still appears vulnerable
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.