Attackers began exploiting a critical vulnerability in Atlassian products hours after a detailed technical report and a public proof-of-concept tool were published. The vulnerability, tracked as CVE-2026-21589, requires no authentication and affects self-hosted Data Center instances of Jira, Confluence, Bitbucket, and other products.
What does the vulnerability enable?
The issue allows an attacker to access specific files within the application’s web root if they know the file name and path precisely. The flaw is linked to a shared library for processing web resources, which converts the string :: into forward slashes, enabling the construction of requests containing path traversal through plugin resource endpoints and the reading of protected files without logging in.
Researchers at watchTowr confirmed that they could read files in Jira, Confluence, and Bitbucket, but their method could not escape the Tomcat application scope and access files outside it.
Affected products
- Bitbucket Data Center
- Confluence Data Center
- Jira Service Management Data Center
- Jira Software Data Center
- Bamboo Data Center
- Crowd Data Center
- Crucible
- Fisheye
Additional risk in Crowd-connected environments
In some Jira deployments integrated with Atlassian Crowd, the files read can be used to access plaintext credentials in the WEB-INF/classes/crowd.properties file. If Crowd is accessible from the network and the application has the necessary permissions, these credentials may allow the creation of an administrator account in Jira through the Crowd API, followed by the creation of users and modification of permissions in the identity management system.
Exploitation becomes more difficult if the IP addresses permitted to access Crowd are restricted, as the attacker may need to route through other devices or use SSRF-like capabilities to access it directly. These conditions mean that the vulnerability’s impact varies according to the deployment architecture and permissions, but it may go beyond mere file reading in unprotected environments.
Why does this matter?
Previdian observed exploitation attempts on its honeypot network within two hours of the publication of watchTowr’s research and proof-of-concept tool. The release of a Nuclei template also made it easier to scan vulnerable systems automatically. The observed attempts included the IP addresses 38.60.157[.]86, 146.70.187[.]234, and 159.26.119[.]225, which the company recommends blocking.
The timeline indicates that publishing actionable details quickly turned the vulnerability from a disclosed issue into a target for automated scanning and exploitation, with the risk expanding because multiple Atlassian products are affected. Previdian expects activity to increase over the coming days and weeks.
What should administrators do?
Atlassian recommended applying the available security updates as soon as possible, while noting that it cannot determine whether customer instances have been compromised. Mitigation measures include restricting external access and using a web application firewall or proxy rule to block the specified path traversal patterns, in addition to Tomcat RewriteValve rules for Confluence, Jira Service Management, Jira, Bamboo, and Crowd products, or a URL rewrite rule in Bitbucket.
watchTowr also released a free scanning tool to help administrators check whether their instances are exposed to the vulnerability. Scan results and audits of accounts and permissions remain particularly important for environments using Crowd, because the source demonstrates the possibility of administrative access only in specific scenarios, not in every deployment.