www.infosecurity-magazine.com 8 Oct 2026, 10:05 UTC

Hackers Exploit Critical Atlassian Flaw to Steal Sensitive Files

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability in Atlassian Data Center products, tracked as CVE-2026-21589, is reportedly being exploited in the wild. Atlassian’s advisory describes it as an arbitrary file access flaw with a CVSS score of 9.3, affecting eight Data Center products that enterprise IT environments commonly rely on. The affected products are Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.

The flaw allows an attacker with no login access to read specific files from each product’s web application root, thanks to vulnerable path handling in a shared Atlassian Web Resource framework component (the atlassian-plugins-webresource library). This shared library explains why seemingly different products are affected and underpins the potential for credential exposure via config files such as Jira’s crowd[.]properties when integrated with Crowd.

Evidence of exploitation has circulated from vulnerability analysis work by WatchTowr, which describes how an unauthenticated attacker could retrieve sensitive files and potentially extract Crowd credentials to abuse Crowd for further access, potentially achieving Jira administrator-level access.

VulnCheck subsequently added CVE-2026-21589 to its KEV list, noting exploitation activity focused on Bamboo Data Center, though the vulnerability had not yet been flagged by the US CISA KEV catalog at the time of reporting.

Atlassian’s patch list specifies fixed versions across all eight products (for example Bitbucket Data Center 9.4.26, 10.2.8 and 10.5.1; Confluence Data Center 9.2.26 and 10.2.19; Jira Service Management Data Center 5.12.40, 10.3.26 and 11.3.12; Jira Software Data Center 9.12.40, 10.3.26 and 11.3.12; Bamboo Data Center 10.2.24 and 12.1.12; Crowd Data Center 6.3.7, 7.0.3, 7.1.7 and 7.2.4; Crucible 4.9.15; Fisheye 4.9.15).

Organisations are advised to apply patches or, if patching is not possible, implement mitigations such as a WAF rule, Tomcat RewriteValve rules for selected products, or urlrewrite[.]xml rules for Bitbucket, and to review for signs of compromise with assistance from security teams. WatchTowr has released a detection artefact generator to help verify exposure in Jira, Confluence and Bitbucket.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline