Full Report
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software
Analysis Summary
# Vulnerability: Critical Arbitrary File Access in Atlassian Data Center Products
## CVE Details
- **CVE ID:** CVE-2026-21589
- **CVSS Score:** 9.3 (Critical)
- **CWE:** Path Traversal / Arbitrary File Access
## Affected Systems
- **Products:**
- Bitbucket Data Center
- Confluence Data Center
- Jira Service Management Data Center
- Jira Software Data Center
- Bamboo Data Center
- Crowd Data Center
- Crucible
- Fisheye
- **Versions:**
- Bitbucket: Versions prior to 9.4.26, 10.2.8, 10.5.1
- Confluence: Versions prior to 9.2.26, 10.2.19
- JSM/Jira Software: Versions prior to 5.12.40, 9.12.40, 10.3.26, 11.3.12
- Bamboo: Versions prior to 10.2.24, 12.1.12
- Crowd: Versions prior to 6.3.7, 7.0.3, 7.1.7, 7.2.4
- Crucible/Fisheye: Versions prior to 4.9.15
- **Configurations:** Systems exposed to the public internet; configurations where sensitive files (e.g., `crowd.properties`) reside within the webroot.
## Vulnerability Description
The flaw resides in Atlassian’s web-resource handling logic. The application improperly resolves specific string patterns, converting sequences such as `..::..::` into standard path traversal sequences like `../../`. An unauthenticated attacker can abuse this by targeting specific plugin resource paths (e.g., `/download/resources/jira.webresources:color-picker-popup/images/`) and appending the malicious path resolution string to access files within the web application root directory. While it does not allow directory listing, it permits the retrieval of known sensitive files.
## Exploitation
- **Status:** Exploited in the wild (attempts detected within two hours of public disclosure); PoC available via watchTowr and Nuclei templates.
- **Complexity:** Low
- **Attack Vector:** Network (Remote/Unauthenticated)
## Impact
- **Confidentiality:** High (Access to sensitive files, credentials, and configuration files).
- **Integrity:** High (Leaked credentials can lead to administrative access and unauthorized account creation).
- **Availability:** Low/Medium (Indirectly through unauthorized system modifications).
## Remediation
### Patches
Update to the following versions or higher:
- **Bitbucket:** 9.4.26, 10.2.8, 10.5.1
- **Confluence:** 9.2.26, 10.2.19
- **Jira / JSM:** 5.12.40, 9.12.40, 10.3.26, 11.3.12
- **Bamboo:** 10.2.24, 12.1.12
- **Crowd:** 6.3.7, 7.0.3, 7.1.7, 7.2.4
- **Crucible/Fisheye:** 4.9.15
### Workarounds
- Disconnect affected instances from the public internet.
- Implement Web Application Firewall (WAF) rules to block suspicious path traversal patterns.
- **Tomcat (Confluence, Jira, Bamboo, Crowd):** Use `RewriteValve` to block malicious requests.
- **Bitbucket:** Add a new blocking rule to `urlrewrite.xml`.
## Detection
- **Indicators of Compromise (IPs):**
- 38.60.157[.]86
- 146.70.187[.]234
- 159.26.119[.]225
- **Detection Methods:** Monitor web server logs for GET requests containing `..::` or attempts to access `WEB-INF/web.xml` or `crowd.properties` via the `/download/resources/` endpoint.
## References
- Atlassian Advisory: hxxps://thehackernews[.]com/2026/10/critical-atlassian-flaw-lets.html
- Previdian Telemetry: hxxps://previdian[.]com/CVE-2026-21589
- watchTowr Research/PoC: hxxps://github[.]com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589