Critical Atlassian CVE-2026-21589 Exploited After Public PoC Release
A critical vulnerability tracked as CVE-2026-21589 is being exploited against multiple Atlassian product families, including Jira, Confluence, and Bitbucket. The unauthenticated flaw can allow attackers to access certain files in an application’s web root directory.
Security firm Previdian detected exploitation attempts on its honeypot network just hours after researchers published detailed technical information and a public proof-of-concept (PoC).
Atlassian CVE-2026-21589 enables arbitrary file access
CVE-2026-21589 is an arbitrary file access vulnerability affecting self-hosted instances of eight Atlassian products:
- Bitbucket Data Center
- Confluence Data Center
- Jira Service Management Data Center
- Jira Software Data Center
- Bamboo Data Center
- Cloud Data Center
- Crucible
- FishEye
The flaw can be exploited by an unauthenticated attacker who knows the exact file name and path. In a security advisory issued Monday, Atlassian said it could not determine whether individual customer instances had been compromised and urged administrators of self-hosted deployments to apply security updates as soon as possible.
Public exploit shows possible Jira administrator takeover
Offensive security company watchTowr published a technical report demonstrating how CVE-2026-21589 can be exploited to access files without authentication and, in certain Crowd integration deployments, gain administrator-level access to Jira, Confluence, and Bitbucket.
Atlassian Crowd provides centralized identity management, single sign-on (SSO), authentication, authorization, and access management for connected Data Center applications.
Researchers traced the vulnerability to a shared web resource library that converts double colons (::) into slashes (/). By abusing this behavior through plugin resource endpoints, attackers can perform directory traversal and retrieve protected application files without authenticating.
watchTowr researchers observed file access in Jira, Confluence, and Bitbucket. However, their technique could not traverse outside the Tomcat application context.
In a Jira deployment integrated with Crowd, an attacker could read plaintext application credentials from WEB-INF/classes/crowd.properties. Those credentials could then be used to create a Jira administrator account through Crowd’s API.
This escalation scenario requires Crowd to be reachable and the application to have sufficient permissions. The researchers noted that restricting access to a specific list of allowed IP addresses would make exploitation significantly more difficult.
“To access Crowd directly, you must pivot through any machine or use features like SSRF in Jira, Confluence, or Bitbucket,” the researchers said.
Credentials exposed in crowd.properties can provide administrative access to the Crowd identity management system, allowing an attacker to create users and modify permissions.

Source: watchTowr
Exploitation began shortly after PoC publication
According to Previdian, the technical details published by watchTowr were sufficient for threat actors to scan and investigate exposed vulnerable instances.
“Within two hours of watchTowr publishing the technical research and public PoC for CVE-2026-21589, Previdian’s honeypot network began observing attempts to exploit this vulnerability,” Previdian’s Ryan Dewhurst told BleepingComputer.
“Nuclei templates have also been released, making it much easier to automate scanning for vulnerable systems.”
Previdian has so far observed three exploitation attempts originating from the following IP addresses:
38.60.157.[.]86146.70.187[.]234159.26.119[.]225
Dewhurst expects exploitation to increase significantly in the coming days and weeks because of the rapid emergence of attacks following public PoC releases, the availability of automated scanning templates, and the broad impact across Atlassian products.
How to protect affected Atlassian systems
System administrators should apply available security updates or recommended mitigations as soon as possible.
Recommended protections include:
- Restricting external network access to affected Atlassian applications.
- Adding web application firewall (WAF) or proxy rules to block the specified traversal patterns across affected products.
- Applying Tomcat RewriteValve rules for Confluence, Jira Service Management, Jira, Bamboo, and Crowd.
- Applying URL rewrite rules for Bitbucket.
For fixed versions and detailed mitigation guidance, consult Atlassian’s security advisory.
watchTowr has also released a free scanner tool to help administrators determine whether their instances are vulnerable to CVE-2026-21589.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com




