Exploitation attempts have begun against a critical arbitrary file access vulnerability, CVE-2026-21589, affecting multiple self-managed Atlassian Data Center products. The attempts were observed by threat intelligence vendor Previdian on Tuesday, just one day after Atlassian released patches and hours after security researchers published a technical analysis of the flaw.
The vulnerability impacts all versions of Atlassian's Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Successful exploitation could allow attackers to access specific files within the web application root directory of vulnerable instances. Atlassian confirmed that exploitation requires prior knowledge of the target file's exact name and path, as the vulnerability does not allow for directory enumeration. However, the company noted that certain configurations may contain sensitive files, increasing the risk.
Offensive security firm watchTowr identified the root cause of CVE-2026-21589 in the `atlassian-plugins-webresource*.jar` library, which is shared across the affected products. Their analysis revealed a flaw in the routing code that converts double colons (`::`) into forward slashes (`/`). This allows an attacker to bypass existing slash-stripping defenses by crafting a path-traversal payload such as `..::..::..::dir::file.txt` through a resource-serving route.
WatchTowr demonstrated this by using a color-picker plugin route in Jira to read the `WEB-INF/web.xml` file, which is typically protected. They also noted equivalent routes exist for Confluence and Bitbucket. While a file read alone might not immediately seem critical, the researchers followed Atlassian's hint about sensitive files in certain configurations. They discovered that Atlassian Crowd deployments store `crowd.properties` under `WEB-INF/classes`, which contains the application name and password in plaintext.
With these leaked credentials, an attacker could directly interact with Atlassian Crowd, the company's identity and single sign-on (SSO) hub. This access would enable them to list users, create new accounts, and add them to privileged groups like `jira-administrators`, effectively granting them administrative control over Jira. WatchTowr developed a proof-of-concept exploit, though they did not publish it, and provided a script for customers to check if their Jira, Confluence, or Bitbucket instances are vulnerable.
Atlassian has strongly urged customers to upgrade to a fixed version as soon as possible. For those unable to patch immediately, the company recommends removing vulnerable instances from the internet or blocking external network access until an upgrade can be performed. Additionally, Atlassian advises customers to review their access logs for specific indicators of compromise by analyzing request lines.






