Atlassian patches critical unauthenticated file-read flaw in Data Center
Unauthenticated CVE-2026-21589 can read known files on Atlassian Data Center products; honeypot probes reached 190 by October 8.
On October 5, 2026, Atlassian disclosed CVE-2026-21589, a critical unauthenticated arbitrary file-access flaw scored CVSS 9.3 in customer-managed Data Center software. Most accounts name eight products—Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye—though The Hacker News and Help Net Security omit Jira Service Management, and an October 7 SecurityWeek report also refers to server products. Attackers who already know an exact path can read named files under the web-application root but cannot list directories; CSO Online says traversal may reach outside that root, while Rapid7 says reads remain inside the Tomcat context, and watchTowr traced the issue to double-colon handling in atlassian-plugins-webresource while citing roughly 700,000 internet-facing Confluence instances. Atlassian Cloud is patched, Security Affairs cites fixed builds including Bitbucket 9.4.26, 10.2.8, and 10.5.1 and Confluence 9.2.26 and 10.2.19, and WAF, rewrite, and isolation steps are described only as temporary alternatives to upgrading. Early statements of no exploitation were overtaken by Previdian honeypot reports—15 attempts from three addresses in Japan and the United States about two hours after watchTowr’s details and a public proof of concept, then 190 attempts from 32 IPs in 10 countries by October 8—while Infosecurity Magazine says VulnCheck recorded Bamboo-targeted activity, CISA has not added the bug to KEV, and sources warn that crowd.properties can leak plaintext credentials usable for administrative access.
- On October 5, 2026, Atlassian disclosed CVE-2026-21589, an unauthenticated arbitrary file-access flaw rated CVSS 9.3.
- Most reports list eight customer-managed products—Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye Data Center—while The Hacker News and Help Net Security omit Jira Service Management, and…
- An attacker who already knows an exact path can read named web-root files but cannot list directories; CSO Online says traversal may reach outside that root, while Rapid7 says reads stay inside the Tomcat context.
- watchTowr traced the bug to double-colon path handling in the shared atlassian-plugins-webresource library and cited roughly 700,000 internet-facing Confluence instances.
- Atlassian Cloud is patched; Security Affairs cites fixed Data Center builds including Bitbucket 9.4.26, 10.2.8, and 10.5.1 and Confluence 9.2.26 and 10.2.19, with other product fixes also shipped.
- Early reports said no exploitation was seen; Previdian later logged 15 honeypot attempts from three IPs in Japan and the United States about two hours after public details, then 190 attempts from 32 IPs in 10 countries by October 8.
- Infosecurity Magazine says VulnCheck listed the flaw on October 7 after Bamboo targeting, while CISA had not added it to KEV and Atlassian has not confirmed customer compromises.
- Reading crowd.properties on Crowd-integrated deployments can expose plaintext credentials usable to create administrators; a public proof of concept and Nuclei template exist, and WAF or rewrite rules are only temporary alternatives to…
Coverage timelineoldest first · each row is one article
- · 2d agoAtlassian warns of critical file access flaw in its datacenter products
The Register · Security· 76
Atlassian urges patches for CVE-2026-21589, an unauthenticated file-read flaw in eight Data Center products.
- · 2d agoCritical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
The Hacker News· 76
CVE-2026-21589 lets unauthenticated attackers read known files in eight self-hosted Atlassian Data Center products.
- · 2d ago
Vulnerabilities in this storyAll →
- CVE-2026-215899.32%This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access…published PoC ×7
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21589 | This: Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access… |