Skip to main content
Emerging ThreatsMalware & Ransomware

Atlassian Flaw Exploited in Wild After Public PoC Release

Server room interior with rows of racks and a single workstation.

"Within two hours of watchTowr publishing its technical research and public PoC for CVE-2026-21589, Previdian's honeypot network began observing exploitation attempts targeting the vulnerability," Previdian’s Ryan Dewhurst told BleepingComputer.

CVE-2026-21589: scope and mechanics

The flaw tracked as CVE-2026-21589 is an unauthenticated arbitrary file‑access vulnerability that affects self‑hosted instances across eight Atlassian product families: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. An attacker who knows the exact filename and path can request and retrieve specific files from an application's web root without authenticating.

watchTowr identified the root cause in a shared web‑resource library that converts double colons ("::") into forward slashes ("/"). Researchers used that behavior to construct directory‑traversal requests via plugin resource endpoints to read protected application files.

watchTowr PoC: file reads and Crowd escalation

In technical reporting and a public proof‑of‑concept, watchTowr confirmed that the technique can read files in Jira, Confluence, and Bitbucket. The researchers noted a key constraint: their approach could not traverse outside the Tomcat application context. That limitation matters for what files are reachable from a given app instance.

In Crowd‑integrated Jira deployments, however, the researchers showed a specific escalation path. An attacker able to read WEB-INF/classes/crowd.properties can obtain plaintext application credentials. If Crowd is reachable and the application account has sufficient permissions, those leaked credentials allow an attacker to create a Jira administrator account through Crowd’s API. watchTowr emphasized that specifying an allowed‑IP list for Crowd materially raises the difficulty of this escalation: an attacker would otherwise need to pivot through other machines or use SSRF‑like capabilities in Jira, Confluence, or Bitbucket to reach Crowd directly.

Previdian detection, automation, and observed indicators

The quick move from public disclosure to exploitation was documented by Previdian. Within hours of watchTowr’s public technical report and PoC, the security company’s honeypot network began seeing exploit attempts. Previdian reported that a Nuclei template has been released, lowering the bar for automated scanning of exposed instances.

Previdian has observed exploitation attempts from three IP addresses and recommends blocking them: 38.60.157[.]86, 146.70.187[.]234, and 159.26.119[.]225. Ryan Dewhurst told BleepingComputer he expects exploitation activity to increase significantly in the coming days and weeks, citing the rapid uptake after the public PoC, available automated scanning templates, and the broad set of affected products.

Atlassian advisory and recommended mitigations

Atlassian published a security advisory on Monday urging administrators of self‑hosted instances to apply security updates immediately. The company noted it cannot determine whether individual customer instances have been compromised, and it directed administrators to fixed versions and mitigation steps in its bulletin.

Administrators who cannot immediately apply updates are advised to apply recommended mitigations. Those steps include restricting external network access to affected services; adding a web application firewall (WAF) or proxy rule that blocks the traversal patterns watchTowr exploited; Tomcat RewriteValve rules for Confluence, Jira Service Management (JSM), Jira, Bamboo, and Crowd; or a URL rewrite rule for Bitbucket.

watchTowr has also released a free scanner tool to help administrators determine whether their instances are vulnerable to CVE-2026-21589.

What this means for administrators and identity managers

  • Administrators of self‑hosted Atlassian apps: apply the security updates Atlassian published as soon as possible and follow the bulletin’s mitigation checklist if a patch cannot be deployed immediately. Assume exposure is possible until verification is completed; the advisory states Atlassian cannot determine which customer instances, if any, were compromised.
  • Identity managers and Crowd operators: ensure Crowd is not directly reachable from affected application contexts and consider restricting Crowd access by allowed‑IP lists. The reported escalation depends on Crowd being reachable and the application possessing sufficient permissions to act via Crowd’s API.

The chain from a shared resource library quirk to unauthenticated file reads—and in some deployments, to administrator creation via Crowd—illustrates how a single implementation detail can cascade into high‑impact risk. With a public PoC, automated scanning templates, observed exploit attempts, and a published set of mitigations and fixes, the immediate imperative is clear: apply patches now and verify the integrity of sensitive files such as WEB-INF/classes/crowd.properties.

Original reporting: https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-atlassian-flaw-after-public-poc-release/