One day after Atlassian released patches fixing a critical arbitrary file access vulnerability (CVE-2026-21589) in its self-managed Data Center products, and a few hours after watchTowr researchers published a technical rundown of the flaw, attackers have been spotted attempting to exploit it.
CVE-2026-21589 PoC in action (Source: watchTowr)
“Exploitation attempts have now started to hit our honeypot network,” threat intelligence vendor Previdian warned late Tuesday, and shared a list of attacker IPs.
About CVE-2026-21589
CVE-2026-21589 affects all versions of Atlassian’s Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.
Successful exploitation may allow attackers to access specific files within the web application root directory of vulnerable instances.
“In some configurations, there may be sensitive files present that increase your risk,” Atlassian said, but added that “exploitation requires prior knowledge of the target file’s exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents.”
CVE-2026-21589: The technical details
Offensive security firm watchTowr dug into the fixes to pinpoint the cause of CVE-2026-21589, and traced it to atlassian-plugins-webresource*.jar, a library shared by the vulnerable solutions.
By comparing the vulnerable JAR and the patched one, watchTowr found a quirk in the routing code: functions that convert double colons (::) into forward slashes (/). That lets an attacker smuggle a path-traversal payload shaped like ..::..::..:: through a resource-serving route whose slash-stripping defenses are effectively bypassed.
Using a color-picker plugin route in Jira, they read the normally protected WEB-INF/web.xml, and showed equivalent routes for Confluence and Bitbucket. Effectively, they were able to read any file within the application server.
File read alone didn’t seem to justify a critical rating, so they followed the advisory’s hint that some configurations hold sensitive files.
They found that Atlassian Crowd deployments store crowd.properties under WEB-INF/classes, containing the application name and password in plaintext.
With those leaked credentials, an attacker can “talk” directly to Crowd, Atlassian’s identity and SSO hub, to list users, create new accounts, and add them to groups like jira-administrators, effectively becoming a Jira admin.
watchTowr created (but did not publish) a PoC exploit, and provided a script that can be used to check whether a target Jira, Confluence or BitBucket instance is vulnerable to CVE-2026-21589.
Atlassian urged customers to upgrade to a fixed version as soon as possible.
Those who can’t do it quickly have been advised to remove their vulnerable instances from the internet until they can, or block access to it from external networks.
Finally, Atlassian advised customers to check for evidence of compromise by analyzing access-log request lines for specific indicators.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!


