DKDKCISSPSearch
VulnerabilitiesDEVELOPING

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions.

DKCISSP News DeskThe Hacker News7 Oct 2026, 5:19 pm
Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions.

The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye.

Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket.

- The exploitation activity targeting its honeypot network is said to have begun two hours after watchTowr released more technical details of the vulnerability , stating it allows unauthenticated attackers to retrieve sensitive files within the webroot directory through a single request and extract tokens, credentials, keys, or other authentication material.

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory.

In some configurations, there may be sensitive files present that increase your risk." Atlassian said impacted Atlassian Cloud products have been patched, adding that fixes are available for the following products - As temporary mitigation, Atlassian is recommending that customers remove their instance from the public internet, apply a Web Application Firewall (WAF) rule, block requests using Tomcat's RewriteValve (for Confluence, JSM, Jira, Bamboo, and Crowd), and add a new rule to urlrewrite.xml (for Bitbucket).

According to the preemptive exposure management firm, the underlying vulnerability has to do with Atlassian's web-resource handling, which converts a string like "..::..::..::..::WEB-INF::web.xml" to "../../../../WEB-INF/web.xml." As a result, an unauthenticated attacker with knowledge of the resource-resolution logic can abuse this path resolution logic and combine it with an Atlassian "/includes/jquery/plugins/colorpicker/images/" plugin resource by taking advantage of the trailing "/" to reach other files (e.g., "WEB-INF/web.xml") elsewhere in the application - Importantly, in the case of Atlassian Crowd and Jira, the attacker could exploit the flaw to access "WEB-INF/classes/crowd.properties," which stores Crowd credentials, and then use them to gain administrative access to the application.

CVE-2021-26086 is a path traversal vulnerability in Jira Server and Data Center that allows remote attackers to read specific files.

According to telemetry data from Previdian, a total of 15 exploitation attempts have been detected from three unique IP addresses located in Japan and the U.S.

CVE-2026-21589 affects all product versions released before the releases listed below, which address the vulnerability: Atlassian urges system administrators who manage self-hosted instances to apply the security updates immediately.

What happened

Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions.

The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye.

What changed

Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket.

- The exploitation activity targeting its honeypot network is said to have begun two hours after watchTowr released more technical details of the vulnerability , stating it allows unauthenticated attackers to retrieve sensitive files within the webroot directory through a single request and extract tokens, credentials, keys, or other authentication material.

Who is affected

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory.

In some configurations, there may be sensitive files present that increase your risk." Atlassian said impacted Atlassian Cloud products have been patched, adding that fixes are available for the following products - As temporary mitigation, Atlassian is recommending that customers remove their instance from the public internet, apply a Web Application Firewall (WAF) rule, block requests using Tomcat's RewriteValve (for Confluence, JSM, Jira, Bamboo, and Crowd), and add a new rule to urlrewrite.xml (for Bitbucket).

Why it matters

According to the preemptive exposure management firm, the underlying vulnerability has to do with Atlassian's web-resource handling, which converts a string like "..::..::..::..::WEB-INF::web.xml" to "../../../../WEB-INF/web.xml." As a result, an unauthenticated attacker with knowledge of the resource-resolution logic can abuse this path resolution logic and combine it with an Atlassian "/includes/jquery/plugins/colorpicker/images/" plugin resource by taking advantage of the trailing "/" to reach other files (e.g., "WEB-INF/web.xml") elsewhere in the application - Importantly, in the case of Atlassian Crowd and Jira, the attacker could exploit the flaw to access "WEB-INF/classes/crowd.properties," which stores Crowd credentials, and then use them to gain administrative access to the application.

CVE-2021-26086 is a path traversal vulnerability in Jira Server and Data Center that allows remote attackers to read specific files.

Technical details

According to telemetry data from Previdian, a total of 15 exploitation attempts have been detected from three unique IP addresses located in Japan and the U.S.

CVE-2026-21589 affects all product versions released before the releases listed below, which address the vulnerability: Atlassian urges system administrators who manage self-hosted instances to apply the security updates immediately.

Attackers have exploited this kind of flaw in an Atlassian product before.

Response

Atlassian's cloud products affected by the flaw have already been patched, and cloud customers do not need to take any action.

Atlassian said it currently has no evidence that CVE-2026-21589 is being exploited in attacks, but urges administrators to review access logs for the traversal patterns described in the bulletin.

What security teams should do

Organizations running affected Atlassian products should treat patching as an immediate priority."

If immediate patching is not possible, the company recommends restricting external network access, including for internet-facing instances that require user authentication.

Attribution

The Hacker News: Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions.

BleepingComputer: Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket.

The Hacker News: A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN VULNERABILITIES

More cybersecurity reporting

Atlassian warns of critical file-access flaw in Jira, ConfluenceBleepingComputer · 6 Oct 2026, 11:04 pmRed Hat’s Lightwell Project Remediates 400 Open-Source VulnerabilitiesInfosecurity Magazine · 6 Oct 2026, 6:31 pmDell System Update flaw allows attackers to gain root privileges (CVE-2026-86360) - Help Net SecurityHelp Net Security · 6 Oct 2026, 4:14 pmAttackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCEThe Hacker News · 5 Oct 2026, 8:48 pm