Atlassian Data Center File-Read Flaw CVE-2026-21589 Is Exploited in the Wild Two Days After Disclosure — Honeypots Caught Attacks Two Hours After watchTowr Published Details

Atlassian Data Center File-Read Flaw CVE-2026-21589 Is Exploited in the Wild Two Days After Disclosure — Honeypots Caught Attacks Two Hours After watchTowr Published Details

Atlassian Data Center File-Read Flaw CVE-2026-21589 Is Exploited in the Wild Two Days After Disclosure — Honeypots Caught Attacks Two Hours After watchTowr Published Details

Atlassian's critical file-access flaw in eight Data Center products went from disclosure to active exploitation in under three days. The company published its advisory for CVE-2026-21589 on October 5; on October 7, watchTowr released technical details showing how a single unauthenticated request reads sensitive files from the webroot, and Previdian's honeypots recorded the first exploitation attempts within two hours of that publication. watchTowr is now confirming active, in-the-wild exploitation.

The bug lets an unauthenticated attacker access specific files within the web application root directory of Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd Data Center, plus Crucible and Fisheye — every version is affected before the fixed releases. Exploitation requires prior knowledge of a file's exact name and path; the flaw does not allow directory listing. Atlassian rates it 9.3 under CVSS 4.0: network-reachable, no privileges, no user interaction, high confidentiality impact on the vulnerable system and, unusually, high security-impact ratings across other systems.

watchTowr's write-up shows why the rating is earned rather than conservative. Atlassian's web-resource handling normalizes a string like ..::..::..::..::WEB-INF::web.xml into ../../../../WEB-INF/web.xml, so an attacker can ride the color-picker plugin's resource path and its trailing slash to reach WEB-INF/web.xml in a single request — and, on Crowd and Jira, WEB-INF/classes/crowd.properties, the file that stores Crowd's credentials. Those credentials can grant administrative access, from which an attacker can create users and elevate a rogue account to Jira Administrator. Previdian counted 15 exploitation attempts against its honeypot network from three IP addresses in Japan and the U.S. (38.60.157[.]86, 146.70.187[.]234, 159.26.119[.]225), and CEO Ryan Dewhurst warns that a Nuclei template "will make mass automated scanning even easier, so we expect activity around CVE-2026-21589 to increase quickly."

Fixed versions: Bitbucket 9.4.26, 10.2.8, 10.5.1; Confluence 9.2.26, 10.2.19; Jira Software 9.12.40, 10.3.26, 11.3.12; Jira Service Management 5.12.40, 10.3.26, 11.3.12; Bamboo 10.2.24, 12.1.12; Crowd 6.3.7, 7.0.3, 7.1.7, 7.2.4; Crucible and Fisheye 4.9.15. Cloud customers need to do nothing — Atlassian says cloud instances are patched and its investigation found no evidence of exploitation there. For self-hosted estates, Atlassian cannot confirm whether any instance has been affected; teams are expected to audit their own access logs, URL-decoding each request line up to twice and looking for .. directly adjacent to /, \ or ::. It's the same exploit-after-PoC race we documented with Citrix NetScaler's CVE-2026-8452.

What Should You Do?

  1. Upgrade every Data Center instance to its fixed version — or the nearest fixed LTS release — because all prior versions are vulnerable, including branches that have reached end of life.
  2. If you can't patch today, apply Atlassian's temporary blocking rules: a WAF or reverse-proxy rule that blocks URLs containing .. directly adjacent to /, \ or ::, including URL-encoded forms, for all eight products; Tomcat RewriteValve rules for Confluence, Jira, JSM, Bamboo and Crowd; a urlrewrite.xml rule for Bitbucket.
  3. Take internet-reachable instances offline or restrict them from outside network access until they are upgraded — Atlassian's own advice when an immediate patch isn't possible.
  4. Hunt your logs and rotate secrets: check for the traversal pattern above, and if you run Crowd or Jira, treat crowd.properties credentials and anything reachable through them as potentially compromised.

The WAF Angle

This is the rare advisory where the vendor's official mitigation is a WAF rule: Atlassian explicitly recommends a web application firewall or reverse-proxy block on traversal sequences, because the exploit signature is unusually clean — a literal ::-encoded traversal riding a plugin resource path. Two cautions from our coverage of WAF bypasses: normalization depth matters (decode at least twice, the same way Atlassian's own log-hunting guidance does), and a blocking rule is a bridge, not a destination — the path-resolution logic stays broken until the upgrade lands. The Crowd-to-administrator chain is also a reminder of why file-read bugs earn critical ratings: a readable crowd.properties is effectively a copy of your authentication secrets, and the requests that steal it look like ordinary static-asset traffic to anything that isn't looking for the shape.

Sources