securityaffairs.com 8 Oct 2026, 07:26 UTC

Hackers Exploit Critical Atlassian Flaw to Steal Restricted Files

Hackers Exploit Critical Atlassian Flaw to Steal Restricted Files
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

THREAT actors are exploiting CVE-2026-21589, a critical arbitrary file access flaw in Atlassian Data Center products, with a CVSS score of 9.3. The vulnerability allows unauthenticated attackers to read specific files from the web application root if they know the exact file name and path.

The issue affects multiple Atlassian Data Centre offerings, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye.

Observed exploitation activity is supported by Previdian telemetry showing 15 exploitation attempts from three IPs in Japan and the United States, and watchTowr Labs published a technical analysis the day prior, highlighting a path traversal weakness that treats double-colon sequences as path separators to reach restricted files such as crowd[.]properties and credentials.

Atlassian lists fixed versions for the affected products and notes that all versions before these are vulnerable: Bitbucket Data Center 9.4.26, 10.2.8, 10.5.1; Confluence Data Center 9.2.26, 10.2.19; Jira Service Management Data Center 5.12.40, 10.3.26, 11.3.12; Jira Software Data Center 9.12.40, 10.3.26, 11.3.12; Bamboo Data Center 10.2.24, 12.1.12; Crowd Data Center 6.3.7, 7.0.3, 7.1.7, 7.2.4; Crucible 4.9.15; Fisheye 4.9.15.

As an immediate precaution, Atlassian recommends taking affected instances offline or behind a Web Application Firewall, and applying vendor patches. For Confluence, Jira Service Management, Jira Software, Bamboo and Crowd, Tomcat’s RewriteValve can block problematic requests; Bitbucket users can modify urlrewrite[.]xml. watchTowr has even released a free tool to help check vulnerability status, and exploitation has been observed on honeypot networks in the hours following the public advisories.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline