Vulnerabilities · Active Exploitation

Attackers Probe Critical Atlassian File-Read Flaw Within Hours of Public PoC

CVE-2026-21589 lets unauthenticated attackers read files in an Atlassian application’s web root — including plaintext credentials in Crowd-integrated Jira deployments. Honeypot operators saw exploitation attempts begin within about two hours of a public proof-of-concept.

Atlassian's Sydney headquarters.
The near-complete Atlassian Central tower, Atlassian’s Sydney headquarters, at Railway Square, photographed October 2026. The company disclosed CVE-2026-21589, an arbitrary file-access flaw affecting eight self-hosted Data Center products.

Photo: Sardaka, CC0, via Wikimedia Commons

Atlassian disclosed a critical arbitrary file-access vulnerability, CVE-2026-21589 (CVSS 9.3, Atlassian rating), in its shared atlassian-plugins-webresource library, affecting eight self-hosted Data Center products: Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye.

Editor’s note on dates: sources disagree on when Atlassian’s advisory was published — CosmicBytez Labs reports Oct 6, while eSecurity Planet and the ervik.as summary place disclosure on Oct 5. We state both below and recommend confirming against Atlassian’s own advisory page.

The flaw

The library converts double-colon sequences (::) into forward slashes during path processing, enabling unauthenticated directory traversal through plugin resource endpoints to read files in the application’s web root. In Crowd-integrated Jira deployments, attackers can extract plaintext credentials from WEB-INF/classes/crowd.properties and escalate to full Jira administrator access, according to CosmicBytez Labs.

From disclosure to exploitation in hours

watchTowr published technical research and a public proof-of-concept on Oct 7. Honeypot operator Previdian observed exploitation attempts within about two hours — 15 attempts from 3 IPs in Japan and the US — and a public Nuclei scanning template followed. Atlassian said it cannot determine whether individual customer instances were compromised, and watchTowr reported no post-compromise action (stolen-credential use) observed at the time of their update.

Atlassian product imagery (Jira/Confluence).
The Atlassian Central headquarters tower under construction at Railway Square, Sydney. Atlassian released fixed versions for all affected products; Cloud products were already patched.

Photo: Sardaka, CC0, via Wikimedia Commons

Fixed versions

Atlassian released fixed versions for all affected products, including Jira Software Data Center 9.12.40, 10.3.26, and 11.3.12; Confluence 9.2.26 and 10.2.19; and Crowd 6.3.7, 7.0.3, 7.1.7, and 7.2.4. Cloud products were already patched. There is no workaround — upgrading to a fixed version is the remediation.

What we know

  • CVE-2026-21589 (CVSS 9.3 per Atlassian) is an arbitrary file-access flaw in the shared atlassian-plugins-webresource library, allowing unauthenticated directory traversal via ::-to-/ conversion.
  • Eight self-hosted Data Center products are affected: Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible, Fisheye.
  • In Crowd-integrated Jira deployments, attackers can extract plaintext credentials from crowd.properties and escalate to full Jira admin.
  • watchTowr published technical research and a public PoC on Oct 7; Previdian observed exploitation attempts within ~2 hours (15 attempts from 3 IPs in Japan and the US).
  • Fixed versions released for all affected products; Cloud already patched; no workaround exists.

What remains unknown

  • The exact advisory date — sources report Oct 5 or Oct 6 (see editor’s note above).
  • Whether any customer instances were actually compromised — Atlassian says it cannot determine this for individual instances.
  • The scale of the exploitation wave; Previdian expects it to rise over coming days and weeks.
  • No post-compromise use of stolen credentials had been observed by watchTowr at the time of their update.

What you can do

  • Upgrade affected Data Center and Server products to the fixed versions immediately — patching is the only remediation.
  • On Crowd-integrated Jira deployments, rotate credentials and treat crowd.properties as potentially exposed.
  • Review logs for requests containing double-colon (::) sequences against plugin resource endpoints.

No corrections have been published for this article.

About the author

Nina Petrova, Correspondent — beat: enterprise security & policy.