
Atlassian Data Center File Flaw Exploited Within Two Hours
A critical arbitrary file access flaw in Atlassian Data Center products drew exploitation attempts two hours after technical details were published; patches are…
Attackers have begun trying to exploit a critical arbitrary file access flaw in Atlassian Data Center products two hours after technical details were made public, according to telemetry from security firm Previdian. The vulnerability, tracked as CVE-2026-21589 and rated 9.3 on the CVSS severity scale, affects self-hosted editions of widely used collaboration and development tools including Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye.
In its advisory, Atlassian explained that the arbitrary file access flaw lets an unauthenticated attacker open specific files inside the web application root directory, which is the folder on the server that holds the application's files. Exploitation requires knowing the exact name and path of the target file, and the flaw does not let an attacker list or browse directory contents. Atlassian said that in some configurations sensitive files may exist in that location, which raises the risk to the organisation running the software. The company has already patched affected Atlassian Cloud products.
Fixed versions are available for self-hosted Data Center installations. These include Bitbucket Data Center 9.4.26, 10.2.8, and 10.5.1; Confluence Data Center 9.2.26 and 10.2.19; Jira Service Management Data Center 5.12.40, 10.3.26, and 11.3.12; Jira Software Data Center 9.12.40, 10.3.26, and 11.3.12; Bamboo Data Center 10.2.24 and 12.1.12; Crowd Data Center 6.3.7, 7.0.3, 7.1.7, and 7.2.4; Crucible 4.9.15; and Fisheye 4.9.15. Atlassian also recommends temporary mitigations for teams that cannot patch immediately: remove the instance from the public internet, apply a Web Application Firewall rule, block requests with Tomcat's RewriteValve for Confluence, Jira Service Management, Jira, Bamboo, and Crowd, and add a new rule to the urlrewrite.xml file for Bitbucket.
The technical cause, according to exposure management firm watchTowr, lies in how Atlassian's web resource handling converts strings. A string like "..::..::..::..::WEB-INF::web.xml" is turned into the path "../../../../WEB-INF/web.xml", which reaches a protected configuration file. An unauthenticated attacker who understands this resource resolution logic can abuse it against an Atlassian plugin resource path that ends with a trailing slash. One example request is GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml. In Atlassian Crowd and Jira, this can be used to read "WEB-INF/classes/crowd.properties", a file that stores Crowd credentials. With those credentials, an attacker can gain administrative access to the application, create new users, modify privileges, and elevate a newly created rogue user to Jira Administrator.
Previdian said its honeypot network, a decoy system designed to attract attacks, recorded 15 exploitation attempts from three unique IP addresses located in Japan and the United States. The addresses are 38.60.157.86, 146.70.187.234, and 159.26.119.225. The activity began two hours after watchTowr published additional technical details, according to the company. Ryan Dewhurst, Previdian's founder and CEO, said the company was already seeing exploitation attempts hit its honeypot network within two hours of public exploit details becoming available. He added that a newly released Nuclei template, a ready-made automated scanning file, will make mass scanning easier and that activity around CVE-2026-21589 is expected to increase quickly. Organisations running affected Atlassian products should treat patching as an immediate priority, Dewhurst warned.
For website owners, businesses and IT teams, this incident is a reminder that self-hosted collaboration and project tools hold sensitive tokens, credentials and configuration files, and that attackers move quickly once technical details appear. Even a single unpatched instance reachable from the internet can become the entry point that exposes the wider environment. Applying the vendor update, removing the application from public internet access where possible, and using a web application firewall all reduce the chance that this flaw is used against the organisation.
For teams that manage self-hosted Atlassian tools, closing the gap between a security advisory and the actual update is a basic operational task. Security-focused IT and consulting, such as the service offered by AEU-I, can help organisations keep patching, access controls and infrastructure hardening part of their routine rather than an emergency response.
How to Protect Yourself
- If your organisation runs any Atlassian Data Center product, ask your IT team to apply the vendor's security update today or do it yourself if you manage it.
- Until you can patch, take the affected application off the public internet or put a web application firewall in front of it to block requests that try to reach sensitive files.
- Change any credentials stored inside the application, especially Crowd credentials or tokens, after patching because they may have been exposed.
- Watch the vendor's security advisory for the exact fixed version for your product and restart the service after updating.
- Avoid exposing admin consoles and internal business tools directly to the internet; keep them behind a VPN or access control.
Vulnerabilities & Fixes
- CVE-2026-21589 Atlassian Data Center arbitrary file access vulnerability; fixed versions are listed in the advisory and temporary mitigations include removing the instance from the public internet and applying WAF rules. View the fix & details →
Terms Explained
- Data Center The self-hosted edition of Atlassian tools that a company installs and runs on its own servers instead of using Atlassian's cloud service.
- Web application root directory The main folder on a server that holds a website's or web app's files, where configuration and sensitive files are often stored.
- Web Application Firewall (WAF) A security filter placed in front of a website that can inspect incoming requests and block malicious or suspicious traffic.
- Honeypot A decoy computer system set up to attract attackers so security researchers can watch what they try to do.
- Nuclei template A pre-made scanning file used by an automated security tool to quickly check many websites for one known weakness.
- Unauthenticated attacker A person or program that can send requests to a system without logging in or having a valid account.
- CVSS score A standard number from 0 to 10 that indicates how severe a software vulnerability is, with higher numbers meaning more serious.