Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
At a glance
- Severity
- Medium
- Used in attacks
- Not on CISA’s list
- Flaws named
- CVE-2026-21589
- Vendors and products
- AtlassianConfluence
- Industries
- SaaS & technology
- Reported by
- 1 outlet
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions.
The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye.
"This arbitrary file access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions," the Australian company said.
"Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be sensitive files present that increase your risk."
Atlassian said impacted Atlassian Cloud products have been patched, adding that fixes are available for the following products -
- Bitbucket Data Center - 9.4.26, 10.2.8, and 10.5.1
- Confluence Data Center - 9.2.26 and 10.2.19
- Jira Service Management Data Center - 5.12.40, 10.3.26, and 11.3.12
- Jira Software Data Center - 9.12.40, 10.3.26, and 11.3.12
- Bamboo Data Center - 10.2.24 and 12.1.12
- Crowd Data Center - 6.3.7, 7.0.3, 7.1.7, and 7.2.4
- Crucible - 4.9.15
- Fisheye - 4.9.15
As temporary mitigation, Atlassian is recommending that customers remove their instance from the public internet, apply a Web Application Firewall (WAF) rule, block requests using Tomcat's RewriteValve (for Confluence, JSM, Jira, Bamboo, and Crowd), and add a new rule to urlrewrite.xml (for Bitbucket).
According to telemetry data from Previdian, a total of 15 exploitation attempts have been detected from three unique IP addresses located in Japan and the U.S. -
- 38.60.157[.]86
- 146.70.187[.]234
- 159.26.119[.]225
The exploitation activity targeting its honeypot network is said to have begun two hours after watchTowr released additional technical details of the vulnerability, stating it allows unauthenticated attackers to retrieve sensitive files within the webroot directory through a single request and extract tokens, credentials, keys, or other authentication material.
According to the preemptive exposure management firm, the underlying vulnerability has to do with Atlassian's web-resource handling, which converts a string like "..::..::..::..::WEB-INF::web.xml" to "../../../../WEB-INF/web.xml."
As a result, an unauthenticated attacker with knowledge of the resource-resolution logic can abuse this path resolution logic and combine it with an Atlassian "/includes/jquery/plugins/colorpicker/images/" plugin resource by taking advantage of the trailing "/" to reach other files (e.g., "WEB-INF/web.xml") elsewhere in the application -
GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml HTTP/1.1
Host: {{Jira-Hostname}}
Importantly, in the case of Atlassian Crowd and Jira, the attacker could exploit the flaw to access "WEB-INF/classes/crowd.properties," which stores Crowd credentials, and then use them to gain administrative access to the application. Armed with this privileged access, it's possible to create new users, modify user privileges, and elevate a newly created rogue user to Jira Administrator.
"Within two hours of public exploit details becoming available, we were already seeing exploitation attempts hit our honeypot network," Previdian Founder and CEO Ryan Dewhurst said in a statement shared with The Hacker News.
"The release of a Nuclei template will make mass automated scanning even easier, so we expect activity around CVE-2026-21589 to increase quickly. Organizations running affected Atlassian products should treat patching as an immediate priority."
Originally published by The Hacker News. © The Hacker News. Written by info@thehackernews.com (The Hacker News).
Vulnerabilities referenced
- CVE-2026-21589Not scored yet
Product not named yet
h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. h3. Context This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. h3. Details: * The vulnerability must be addressed for affected versions of: Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.1, 7.2.4 Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 Crucible, fix versions 4.9.15 Fisheye, fix version 4.9.15 * Exploitation requires prior knowledge of the target file's exact name and path. * The vulnerability does not include the capability to enumerate or list directory contents.
Full record →
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-10-07 11:49 UTC
Related stories
- Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
The Hacker News · 2026-10-07
- PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
The Hacker News · 2026-10-07
- PoeLLM malware infects exposed AI servers in cryptomining attacks
BleepingComputer · 2026-10-07
- Hackers exploit critical Atlassian flaw after public PoC release
BleepingComputer · 2026-10-07
- FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
The Hacker News · 2026-10-07