Atlassian Data Center flaw exploited within hours of disclosure
Attackers targeted CVE-2026-21589 in Atlassian Data Center products just two hours after technical details were published, risking credential theft and admin access.
Bài viết này chỉ có sẵn bằng tiếng Anh.
Threat actors launched exploitation attempts against a critical vulnerability in Atlassian Data Center products merely two hours after technical details became public. The flaw, tracked as CVE-2026-21589, allows unauthenticated attackers to access sensitive files within the web application root directory, posing a severe risk to organizations running affected on-premise instances.
What happened
The vulnerability affects a wide range of Atlassian Data Center products, including Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye. Atlassian assigned the flaw a CVSS score of 9.3, indicating its critical severity. While Atlassian Cloud products were already patched, Data Center customers needed to apply specific updates to secure their environments. The company confirmed that the vulnerability does not allow attackers to list directory contents, but it does permit access to specific files if the attacker knows the exact name and path.
Security firm Previdian detected 15 exploitation attempts from three unique IP addresses located in Japan and the United States shortly after the vulnerability details were released by watchTowr. These attempts targeted honeypot networks designed to capture such activity. The speed of the response highlights the aggressive nature of modern threat actors who monitor public disclosures for immediate exploitation opportunities. The IP addresses identified were 38.60.157[.]86, 146.70.187[.]234, and 159.26.119[.]225.
Atlassian provided fixed versions for all affected products. For example, Jira Software Data Center users must upgrade to versions 9.12.40, 10.3.26, or 11.3.12. Similarly, Confluence Data Center requires version 9.2.26 or 10.2.19. Other products like Bitbucket, Bamboo, and Crowd also have specific patched versions available. Atlassian emphasized that some configurations may contain sensitive files that increase risk, urging customers to prioritize these updates.
How it works
The core of the vulnerability lies in how Atlassian handles web resources. The system converts specific string patterns into file paths. For instance, a string like "..::..::..::..::WEB-INF::web.xml" is translated into "../../../../WEB-INF/web.xml". This conversion logic creates a path traversal opportunity. An unauthenticated attacker can exploit this by combining the flawed resource-resolution logic with a known plugin resource path, such as "/includes/jquery/plugins/colorpicker/images/". By appending the manipulated string to this path, the attacker can traverse directories and access files outside the intended scope.
A typical exploit request might look like a GET request to "/download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml". This single request can retrieve sensitive configuration files. In the case of Atlassian Crowd and Jira, attackers can target "WEB-INF/classes/crowd.properties", which stores Crowd credentials. Accessing this file allows the attacker to gain administrative access to the application. Once inside, they can create new users, modify privileges, and elevate a rogue account to Jira Administrator status, effectively taking control of the instance.
Key details
- Vulnerability ID: CVE-2026-21589 with a CVSS score of 9.3.
- Affected Products: Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye Data Center versions.
- Exploitation Window: Active exploitation attempts detected within two hours of public technical disclosure.
- Attack Vector: Unauthenticated remote attackers can access specific files in the web application root directory.
- Impact: Potential exposure of tokens, credentials, and keys; possible elevation to administrator privileges via Crowd credentials.
- Mitigation: Apply vendor patches, use WAF rules, or implement Tomcat RewriteValve blocks as temporary measures.
Why it matters
For teams managing Atlassian Data Center instances, this incident underscores the critical importance of rapid patch management. The gap between public disclosure and active exploitation has shrunk to hours, leaving little room for delay. Organizations that rely on these tools for code management, project tracking, and documentation face significant risk if they fail to update promptly. The ability for an unauthenticated attacker to extract credentials and gain admin access means that even a single successful exploit can compromise the entire development infrastructure.
Furthermore, the reliance on specific file paths for exploitation means that security teams must understand their application's configuration deeply. While the vulnerability does not allow directory enumeration, the presence of sensitive files like "crowd.properties" in predictable locations makes certain setups more vulnerable. This highlights the need for defense-in-depth strategies, including network segmentation and strict access controls, to limit the impact of such flaws even before patches are applied.
What you can do
- Identify all Atlassian Data Center instances in your environment and check their current versions against the patched lists provided by Atlassian.
- Apply the recommended updates immediately for Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye.
- If immediate patching is not possible, implement temporary mitigations such as removing instances from the public internet or applying WAF rules.
- Block requests using Tomcat's RewriteValve for Confluence, JSM, Jira, Bamboo, and Crowd, or add urlrewrite.xml rules for Bitbucket.
- Monitor logs for suspicious GET requests targeting plugin resource paths with unusual characters like "..::".
- Rotate any credentials stored in "crowd.properties" or similar configuration files if you suspect prior exposure.



