Hackers exploit critical Atlassian flaw after public PoC release

Critical Vulnerability in Atlassian Products Exploited in Attacks After Public PoC Release

A critical vulnerability in multiple Atlassian product families has been exploited by hackers after a detailed technical report was published online. The flaw, identified as CVE-2026-21589, allows an unauthenticated attacker to access specific files in the application’s web root directory if they know the file’s exact name and path.

The issue affects self-hosted instances of eight Atlassian products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. The vulnerability is an arbitrary file-access flaw that can be exploited without requiring authentication.

Security company Previdian detected exploitation attempts on its honeypot network just hours after a technical report was published by watchTowr, an offensive security company. According to Ryan Dewhurst from Previdian, the rapid emergence of exploitation attempts was driven by the availability of automated scanning templates and the broad range of affected Atlassian products.

The researchers exploited the root cause of the flaw, which is a shared web-resource library that converts double colons “::” into forward slashes “/”, to construct directory-traversal requests through plugin resource endpoints. This allowed them to retrieve protected application files without authentication. In Crowd-integrated Jira deployments, attackers could read plaintext application credentials from WEB-INF/classes/crowd.properties and use them to create a Jira administrator account through Crowd’s API.

The leaked credentials in crowd.properties provide administrator access to the Crowd identity management system, allowing attackers to create new users and modify permissions. According to watchTowr researchers, specifying a list of allowed IP addresses would make exploitation significantly more difficult, as attackers would need to pivot through arbitrary machines or use SSRF-like capabilities of Jira, Confluence, or Bitbucket to reach Crowd directly.

The security community has been quick to respond to the vulnerability, with Atlassian issuing a security advisory on Monday and watchTowr releasing a free scanner tool to help administrators determine if their instances are vulnerable. System administrators should apply available security updates as soon as possible, or apply the recommended mitigations, including restricting external network access, adding a web application firewall (WAF) or proxy rule blocking specified traversal patterns across all affected products.

The exploitability of CVE-2026-21589 highlights the importance of keeping software up-to-date and implementing robust security measures to prevent attacks. As Dewhurst expects exploitation activity to increase significantly over the coming days and weeks, system administrators should take immediate action to protect their Atlassian instances.

To mitigate the vulnerability, users can follow these steps: apply available security updates as soon as possible; restrict external network access; add a WAF or proxy rule blocking specified traversal patterns across all affected products; implement Tomcat RewriteValve rules for Confluence, JSM, Jira, Bamboo, and Crowd; or use a URL rewrite rule for Bitbucket. For more details about the fixed versions and mitigation steps, check out Atlassian’s bulletin.

Ultimately, the exploitation of CVE-2026-21589 serves as a reminder to prioritize software security and stay vigilant in the face of emerging threats. By taking proactive measures to protect their systems, users can minimize the risk of falling victim to attacks exploiting this critical vulnerability.


Source: Bleeping Computer — 2026-10-07