Skip to main content
Emerging Threats

Atlassian Vulnerability Exploited in Wild, Targeting Multiple Products

Rows of computer servers and storage equipment in a brightly-lit, empty server room with daylight coming in through tall…

"An arbitrary file access" — that is how Atlassian described CVE-2026-21589 in its October 5 advisory, assigning the flaw a CVSS score of 9.3 and warning that it is being exploited in the wild.

Which Atlassian products are affected and how they are used

CVE-2026-21589 impacts eight Atlassian Data Center products — self‑managed editions that customers run on their own infrastructure. The affected products named by Atlassian are:

  • Bitbucket Data Center: a Git-based source-code management and collaboration tool for hosting repositories, managing code changes and pull requests
  • Confluence Data Center: a team collaboration and knowledge-management platform for documentation, internal wikis, project information and shared knowledge
  • Jira Service Management Data Center: an IT service-management (ITSM) platform used for service desks, incident management, service requests, changes and other IT workflows
  • Jira Software Data Center: a project and software-development management platform used to plan, track and manage software work, including issues, sprints and releases
  • Bamboo Data Center: a continuous integration/continuous delivery (CI/CD) server used to automate software builds, tests and deployments
  • Crowd Data Center: a centralized identity and user-management platform for Atlassian and other applications, providing authentication and user-directory management
  • Crucible: a collaborative code-review tool for reviewing and discussing changes to source code
  • Fisheye: a source-code repository browser and analysis tool that provides visibility into repositories and development activity

Exploitation of CVE-2026-21589 allows an attacker with no login access to read specific files in each product's web application root directory.

The technical root: atlassian-plugins-webresource path-handling

In a vulnerability analysis published October 6, WatchTowr found the products share a common component — the Atlassian Web Resource framework — specifically the atlassian-plugins-webresource library. That shared library contains path‑handling logic that can be bypassed, permitting path‑traversal style access to files in the application webroot. WatchTowr’s finding explains why a single flaw affects multiple, functionally different products: they incorporate the same platform components.

WatchTowr also demonstrated that the arbitrary file‑read can be used to retrieve configuration files such as crowd.properties when Jira is configured to use Crowd. That file contains the credentials Jira uses to communicate with Crowd, and exposing it can expand the impact of the vulnerability beyond simple file disclosure.

Evidence of exploitation: Bamboo targeted, KEV listing added

On October 7, VulnCheck added CVE-2026-21589 to its known exploited vulnerabilities (KEV) list, noting exploitation activity targeting Bamboo Data Center. VulnCheck’s dashboard links to Previdian as a source of exploitation intelligence. At the time of reporting, the vulnerability had not been added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) KEV catalog.

Atlassian’s patches, mitigations, and detection tools

Atlassian published a list of patched versions for the eight affected products and urged customers to upgrade to fixed versions or the latest release. The patched versions listed in the advisory are:

  • Bitbucket Data Center: 9.4.26, 10.2.8 and 10.5.1
  • Confluence Data Center: 9.2.26 and 10.2.19
  • Jira Service Management Data Center: 5.12.40, 10.3.26 and 11.3.12
  • Jira Software Data Center: 9.12.40, 10.3.26 and 11.3.12
  • Bamboo Data Center: 10.2.24 and 12.1.12
  • Crowd Data Center: 6.3.7, 7.0.3, 7.1.7 and 7.2.4
  • Crucible: 4.9.15
  • Fisheye: 4.9.15

For customers unable to patch immediately, Atlassian recommended temporary mitigations including applying a web application firewall (WAF) rule for all affected products, blocking requests using Tomcat’s RewriteValve for Confluence, JSM, Jira, Bamboo and Crowd, and adding a rule to urlrewrite.xml for Bitbucket only. Atlassian further stated it cannot confirm to users whether their instances have been affected and advised customers to engage their local security teams to check affected instances for evidence of compromise.

WatchTowr has released a detection artefact generator for Jira, Confluence and Bitbucket that customers can use to check whether an instance of those products is vulnerable.

How Atlassian customers, security teams, and attackers are affected

Atlassian customers who self‑manage Data Center instances must decide whether to apply the listed patched versions immediately or implement temporary mitigations such as WAF rules and Tomcat or urlrewrite blocks. Security teams will need to search for signs of arbitrary file reads, including exposure of sensitive configuration files like crowd.properties, and to follow Atlassian’s advice to involve local security personnel in any investigation.

Deployments that integrate Crowd as a central identity service face particular risk: WatchTowr showed that harvested Crowd credentials could allow an unauthenticated attacker to interact with Crowd, with potential to create or modify users and privileges — and WatchTowr’s demonstration indicated that sequence “provided a path towards obtaining Jira administrator-level access.” Adversaries already observed exploiting Bamboo Data Center, per VulnCheck, demonstrates that attackers are able and willing to target the flaw in operational environments.

At the center of this episode is a familiar pattern: a shared library embedded across products creates a single point of failure, and a file‑read bug that requires no authentication can cascade from disclosure to account compromise when configuration files carry reusable credentials. The near‑term question for affected organizations is concrete: patch to the listed versions, apply the temporary rules Atlassian recommends if immediate patching is impossible, and hunt for indicators that the file reads were used to escalate access.

https://www.infosecurity-magazine.com/news/critical-vulnerability-atlassian/