Atlassian flaw CVE-2026-21589: exploited two hours after the PoC dropped
Atlassian patched a critical flaw, CVE-2026-21589, that lets attackers read protected files on eight self-hosted products without logging in. The first exploitation attempts came two hours after a proof of concept went public.

Atlassian published a security advisory on Monday 5 October 2026 for CVE-2026-21589, a critical arbitrary file read vulnerability. It affects self-hosted instances of eight products: Jira Software Data Center, Jira Service Management Data Center, Confluence Data Center, Bitbucket Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. An unauthenticated attacker can read files from the application’s web directory — provided they know the exact name and path of what they’re after.
Two colons walk into a parser
The root cause, documented by watchTowr in a technical report released hot on the heels of the advisory, sits in a web resources library shared across the products: it converts double colons — “::” — into forward slashes. That’s the whole trick. The researchers used it to build directory traversal requests through the plugin resource endpoints and read protected files without authenticating. They confirmed file reads on Jira, Confluence and Bitbucket; their technique cannot, however, break out of the Tomcat application context.
The nastiest scenario involves deployments wired into Crowd, Atlassian’s centralised identity management and single sign-on service. On a Jira instance connected to Crowd, the file WEB-INF/classes/crowd.properties stores application credentials in plain text — and watchTowr shows those credentials are all it takes to create a Jira administrator account through Crowd’s API, as long as Crowd is reachable and the application has the right permissions. The same credentials also hand over administrator access to Crowd itself, which means control over accounts and permissions across the board. One consolation: an IP allowlist makes the whole thing considerably harder to pull off.
Two hours from write-up to live fire
According to Bleeping Computer, the company Previdian watched its honeypot network start receiving exploitation attempts on Wednesday 7 October — two hours after watchTowr published its report and proof of concept. A Nuclei template is already making the rounds, automating the hunt for vulnerable instances. Previdian logged three IP addresses behind the attempts — 38.60.157[.]86, 146.70.187[.]234 and 159.26.119[.]225 — recommends blocking them, and expects activity to ramp up sharply over the coming days and weeks.
Patch now, filter while you wait
Atlassian says it has no way of determining whether any given instance has been compromised: that check falls to each administrator. The fixed versions are listed product by product in the vendor’s security bulletin, and the instruction is to apply them as soon as possible.
For instances that can’t be updated right away, the documented mitigations are to restrict external network access, block directory traversal patterns with a web application firewall or proxy, add Tomcat RewriteValve rules for Confluence, Jira, Jira Service Management, Bamboo and Crowd, and a URL rewrite rule for Bitbucket. watchTowr has also released a free scanning tool to check whether an instance is vulnerable.
The patch has been available since Monday; the attack tooling took all of two hours to follow the proof of concept. If you were planning to update at your leisure, that window didn’t close — it was never really open.
Sources (1)
- Hackers exploit critical Atlassian flaw after public PoC releasebleepingcomputer.com
Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.


