isc.sans.edu 7 Oct 2026, 14:59 UTC

Atlassian Patches Flaw Letting Attackers Read Web App Files

Atlassian Patches Flaw Letting Attackers Read Web App Files
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

ATLASSIAN published patches on 5 October 2026 to fix a pre-auth Arbitrary File Access vulnerability across multiple products, tracked as CVE-2026-21589. The flaw is a directory traversal weakness that can let an attacker read arbitrary files within the web application's directory, potentially exposing sensitive configuration data. The vulnerability is unusual in that Atlassian products replace slashes with the pattern ::, and in some cases this escape sequence may be unwound to access files. Watchtowr provide a detailed write‑up with proof‑of‑concept URLs illustrating the attack.

In practice, exploitation hinges on whether the targeted file exists on the server. The honeypot observed exploit attempts using URLs from the Watchtowr post, including attempts to access WEB-INF/web[.]xml within Tomcat-backed paths, with other hits targeting WEB-INF/urlrewrite[.]xml and similar. The attacker pattern translates the :: sequence back to / on the server, enabling a directory traversal within the web app’s directory rather than outside it.

SANS notes that all observed source IPs map to Digital Ocean, listing several addresses such as 134.199.229[.]190 and 143.198.132[.]93 among the observed hits. While the timing and targets suggest a single threat actor, the post emphasises that successful exploitation requires the intended file to exist, and that generic system files like /etc/passwd would not be retrievable in this scenario. Organisations should apply the Atlassian patches promptly and review for any indications of exploitation in their web application directories.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline