Hackers exploit critical Atlassian flaw after public PoC release

Critical Vulnerability in Atlassian Products Exploited by Hackers After Public Disclosure

A critical flaw in multiple Atlassian product families has been exploited by hackers just hours after a detailed technical report was published. The vulnerability, identified as CVE-2026-21589, affects self-hosted instances of eight Atlassian products, including Jira, Confluence, and Bitbucket. What’s more alarming is that the attackers don’t even need to authenticate themselves to access sensitive files.

The issue lies in an arbitrary file-access flaw, which was disclosed on Monday by security company Previdian. The researchers detected exploitation attempts on their honeypot network within two hours of a public technical report being published. The report revealed how hackers can exploit the vulnerability to gain administrator-level access to connected Data Center apps, including Jira, Confluence, and Bitbucket.

The root cause of the flaw is a shared web-resource library that converts double colons “::” into forward slashes “/”, allowing attackers to construct directory-traversal requests through plugin resource endpoints. This enables them to retrieve protected application files without authentication. The researchers confirmed file reads in Jira, Confluence, and Bitbucket, but noted that their technique couldn’t traverse outside the Tomcat application context.

The most concerning aspect of this vulnerability is its impact on Crowd-integrated Jira deployments. Attackers can read plaintext application credentials from WEB-INF/classes/crowd.properties and use them to create a Jira administrator account through Crowd’s API. This could lead to complete control over the system, as attackers would have access to sensitive information.

The rapid emergence of exploitation attempts following the public PoC has raised concerns among security experts. watchTowr researchers expect exploitation activity to increase significantly over the coming days and weeks, driven by the availability of automated scanning templates and the broad range of affected Atlassian products.

To mitigate this vulnerability, system administrators should apply available security updates as soon as possible or implement recommended mitigations. This includes restricting external network access, adding a web application firewall (WAF) or proxy rule blocking specified traversal patterns across all affected products, or applying Tomcat RewriteValve rules for Confluence, JSM, Jira, Bamboo, and Crowd.

For those who haven’t yet applied security updates, Atlassian has released a bulletin detailing the fixed versions and mitigation steps. Additionally, watchTowr has made available a free scanner tool to help administrators determine if their instances are vulnerable to CVE-2026-21589.

The recent exploitation of this critical vulnerability serves as a stark reminder of the importance of timely security updates and proactive threat hunting. As hackers continue to exploit newly disclosed vulnerabilities, it’s essential for system administrators to stay vigilant and take immediate action to protect their systems from these emerging threats.


Source: Bleeping Computer — 2026-10-07