Skip to main content
Emerging Threats

Atlassian Flaw Sees Rapid Exploitation Attempts

Server room interior with focused equipment and cables.

"This arbitrary file access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions," the Australian company said.

CVE-2026-21589 and the affected Atlassian Data Center products

The flaw, tracked as CVE-2026-21589 and carrying a CVSS score of 9.3, affects multiple Atlassian Data Center products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian said impacted Cloud products have been patched and published fixes for Data Center and self-hosted editions.

  • Bitbucket Data Center — 9.4.26, 10.2.8, and 10.5.1
  • Confluence Data Center — 9.2.26 and 10.2.19
  • Jira Service Management Data Center — 5.12.40, 10.3.26, and 11.3.12
  • Jira Software Data Center — 9.12.40, 10.3.26, and 11.3.12
  • Bamboo Data Center — 10.2.24 and 12.1.12
  • Crowd Data Center — 6.3.7, 7.0.3, 7.1.7, and 7.2.4
  • Crucible — 4.9.15
  • Fisheye — 4.9.15

How the vulnerability works: web-resource handling and path resolution

According to technical analysis shared publicly, the root cause lies in Atlassian's web-resource handling and its resource-resolution logic. The handling converts a string like "..::..::..::..::WEB-INF::web.xml" into "../../../../WEB-INF/web.xml". An unauthenticated attacker who understands that logic can combine it with an Atlassian plugin resource path — for example, the "/includes/jquery/plugins/colorpicker/images/" resource — and use a trailing "/" to reach files elsewhere in the application.

The published exploit example shows a single GET request used to retrieve a target file from the webroot:

GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml HTTP/1.1

Host: {{{{Jira-Hostname}}}}

Atlassian noted that exploitation requires prior knowledge of a file's exact name and path; the vulnerability does not enable directory enumeration or listing.

Observed exploitation attempts and telemetry from Previdian

Previdian, a preemptive exposure management firm, reported telemetry indicating 15 exploitation attempts against its honeypot network. Those attempts came from three unique IP addresses located in Japan and the United States: 38.60.157[.]86, 146.70.187[.]234, and 159.26.119[.]225.

Previdian said the activity began two hours after watchTowr released additional technical details of the vulnerability, which described how unauthenticated attackers could retrieve sensitive files within the webroot and extract tokens, credentials, keys, or other authentication material.

Previdian Founder and CEO Ryan Dewhurst said, "Within two hours of public exploit details becoming available, we were already seeing exploitation attempts hit our honeypot network." He also warned that "The release of a Nuclei template will make mass automated scanning even easier, so we expect activity around CVE-2026-21589 to increase quickly."

Specific risk to Crowd and Jira and potential attacker actions

The published analysis highlights a particularly sensitive outcome in Atlassian Crowd and Jira. An attacker able to retrieve "WEB-INF/classes/crowd.properties" could obtain Crowd credentials. Those credentials, the analysis says, could be used to gain administrative access to the application, enabling creation of new users, modification of user privileges, and elevation of a newly created rogue user to Jira Administrator.

Atlassian's mitigations and the urgency for affected organizations

Atlassian recommended immediate mitigations alongside the published fixes. Temporary measures include removing affected instances from the public internet, applying a Web Application Firewall (WAF) rule, blocking requests using Tomcat's RewriteValve for Confluence, Jira Service Management, Jira Software, Bamboo, and Crowd, and adding a new rule to urlrewrite.xml for Bitbucket.

Previdian's advisory reinforces the urgency: "Organizations running affected Atlassian products should treat patching as an immediate priority," Ryan Dewhurst said, noting that easier-to-use scanning templates are likely to accelerate opportunistic exploitation.

For organizations running the listed Data Center versions, the record is clear: patches are available for the affected releases, mitigations are prescribed, and telemetry shows exploitation attempts began within hours of public technical details. Whether scanning and exploitation expand beyond the 15 recorded attempts will depend on how quickly affected instances are patched or isolated.

Source: The Hacker News