THREAT actors began exploiting a newly disclosed critical flaw in Atlassian Data Center products, tracked as CVE-2026-21589 (CVSS 9.3), within two hours of public details. The arbitrary file access vulnerability could allow an unauthenticated attacker to retrieve specific files from the web application root in affected versions, with no directory enumeration; success hinges on knowing the exact file name and path.
In practice, attackers could misuse the web-resource handling logic to traverse to sensitive files such as WEB-INF/web[.]xml, and in the cases of Atlassian Crowd and Jira, could access WEB-INF/classes/crowd[.]properties to obtain credentials and grant themselves administrative rights. The vulnerability’s exposure arises from how Atlassian resolves resource paths, enabling an attacker with knowledge of the resource-resolution logic to chain a crafted path with a legitimate plugin resource to reach restricted files.
Atlassian has patched the underlying cloud-product exposures and provided fixes for specific Data Center versions, including Bitbucket Data Centre 9.4.26, 10.2.8, 10.5.1; Confluence Data Center 9.2.26, 10.2.19; Jira Service Management Data Center 5.12.40, 10.3.26, 11.3.12; Jira Software Data Center 9.12.40, 10.3.26, 11.3.12; Bamboo Data Center 10.2.24, 12.1.12; Crowd Data Center 6.3.7, 7.0.3, 7.1.7, 7.2.4; Crucible 4.9.15; and Fisheye 4.9.15.
As a temporary mitigation, Atlassian recommends removing public internet exposure, applying a Web Application Firewall rule, blocking Tomcat’s RewriteValve for affected products, and updating urlrewrite[.]xml where applicable. Telemetry from Previdian detected 15 exploitation attempts from three IPs across Japan and the United States, underscoring the need for immediate patching in affected environments.