Critical Flaw in Multiple Atlassian Products Exploited in the Wild

Written by

A critical vulnerability in Atlassian Data Center products is reportedly being exploited in the wild.

The flaw, tracked as CVE-2026-21589, was described by Atlassian in an October 5 advisory as an arbitrary file access, with a severity score (CVSS) of 9.3.

It affects eight Atlassian products, widely used in enterprise IT systems:

  • Bitbucket Data Center: a Git-based source-code management and collaboration for software development teams, used to host repositories, manage code changes and pull requests
  • Confluence Data Center: a team collaboration and knowledge-management platform, used for documentation, internal wikis, project information and shared knowledge
  • Jira Service Management Data Center: an IT service-management (ITSM) platform, used for service desks, incident management, service requests, changes and other IT workflows
  • Jira Software Data Center: a project and software-development management platform, used to plan, track and manage software work, including issues, sprints and releases
  • Bamboo Data Center: a continuous integration/continuous delivery (CI/CD) server used to automate software builds, tests and deployments
  • Crowd Data Center: a centralized identity and user-management platform for Atlassian and other applications, providing capabilities such as authentication and user-directory management
  • Crucible: a collaborative code-review tool, allowing developers to review and discuss changes to source code
  • Fisheye: a source-code repository browser and analysis tool, providing visibility into code repositories and development activity

The “data center” products are self-managed versions of Atlassian products, where the customer runs the software and manages the underlying infrastructure, rather than Atlassian hosting and operating it as software-as-service (SaaS). They typically are hosted in the company’s own data center or on infrastructure it controls in a public cloud such as AWS or Azure.

Exploiting CVE-2026-21589 allows an attacker with no login access to read specific files in each product's web application root directory.

Evidence of CVE-2026-21589 Exploitation Targeting Bamboo Data Center

In a vulnerability analysis published on October 6, WatchTowr found that the affected Atlassian products share a common Atlassian Web Resource framework, specifically the atlassian-plugins-webresource library. This shared library contains the vulnerable path-handling logic that allows an attacker to bypass path-traversal protections and read files from the application's webroot.

This explains why CVE-2026-21589 affects seemingly different products: they incorporate common Atlassian platform components, including this Web Resource library.

WatchTowr added that while Atlassian Crowd is also more than just one of the affected products, it plays an important role in the potential attack chain because it can be used as a central identity and authentication service for other Atlassian products. For example, when Jira is configured to use Crowd, Jira's crowd.properties configuration file contains the credentials that Jira uses to communicate with Crowd.

WatchTowr demonstrated that the arbitrary file-read vulnerability can be used to retrieve this file and expose those credentials.

This means the vulnerability can potentially go beyond simply reading files: an unauthenticated attacker could exploit CVE-2026-21589 to obtain Crowd credentials from an integrated Atlassian application and then use those credentials to interact with Crowd, potentially creating or modifying users and privileges.

In WatchTowr's demonstration, this provided a path towards obtaining Jira administrator-level access.

On October 7, VulnCheck added CVE-2026-21589 to its known exploited vulnerabilities (KEV) list, observing exploitation activity targeting Bamboo Data Center. VulnCheck’s dashboard links to Previdian as a source of exploitation intelligence.

The vulnerability has not been added to the US Cybersecurity and Infrastructure Securiy’s (CISA) own KEV catalog at the time of writing.

Atlassian’s Patch and Mitigation Recommendations

In its advisory, Atlassian provides the list of patched versions for each of the eight products affected by CVE-2026-21589:

  • Bitbucket Data Center (9.4.26, 10.2.8 and 10.5.1)
  • Confluence Data Center (9.2.26 and 10.2.19)
  • Jira Service Management Data Center (5.12.40, 10.3.26 and 11.3.12)
  • Jira Software Data Center (9.12.40, 10.3.26 and 11.3.12)
  • Bamboo Data Center (10.2.24 and 12.1.12)
  • Crowd Data Center (6.3.7, 7.0.3, 7.1.7 and 7.2.4)
  • Crucible (4.9.15)
  • Fisheye (4.9.15)

Customers are urged to patch each of their affected installations to fixed versions or the latest version.

If they cannot patch, Atlassian also recommended temporary mitigations that include:

  1. Applying a web application firewall (WAF) rule (for all affected products)
  2. Blocking requests using Tomcat’s RewriteValve (for Confluence, JSM, Jira, Bamboo and Crowd)
  3. Adding a rule to urlrewrite.xml (for Bitbucket only)

Atlassian said it cannot confirm to users whether their instances have been affected by this vulnerability and recommended that customers engage with their local security team to check all affected instances for evidence of compromise.

WatchTowr has released a detection artefact generator for Jira, Confluence and Bitbucket that Atlassian customers can use to check whether an instance of any of these three product ranges is vulnerable.

Image credits: Fanta Media / bluestork / Shutterstock.com

What’s Hot on Infosecurity Magazine?