Exploitation of a critical security vulnerability in Atlassian Data Center products commenced swiftly after details were made public. The flaw, identified as CVE-2026-21589 with a CVSS score of 9.3, impacts several Atlassian products, posing a significant risk to sensitive data.
Details of the Vulnerability
The vulnerability allows unauthorized access to specific files within the affected products’ web application root directory. Products impacted include Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Exploitation requires knowledge of the exact file name and path, although it does not allow directory content listing.
Atlassian has addressed the issue in its cloud products and provided patches for the affected versions. The updates are available for Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye, with various version numbers specified for each product.
Mitigation and Exploitation Attempts
As a temporary measure, Atlassian advises removing affected instances from public internet access and implementing a Web Application Firewall (WAF) rule. Additional steps include blocking requests via Tomcat’s RewriteValve and modifying the urlrewrite.xml file for Bitbucket.
Previdian’s telemetry data revealed 15 exploitation attempts originating from three distinct IP addresses in Japan and the U.S. These attempts began shortly after watchTowr released technical details, which highlighted the ability of attackers to access sensitive files and extract critical authentication material.
Path to Resolution and Future Outlook
The flaw is linked to Atlassian’s web-resource handling, which converts specific strings to file paths, allowing attackers to access files like “WEB-INF/web.xml.” This can lead to unauthorized access to credentials stored in files such as “crowd.properties,” enabling attackers to manipulate user privileges.
Previdian’s CEO, Ryan Dewhurst, noted the rapid onset of exploitation attempts and emphasized the critical need for affected organizations to prioritize patching. With the release of a new Nuclei template, automated scanning is expected to escalate, increasing the urgency for protective measures.
Organizations using Atlassian products are urged to act swiftly in applying the available patches to safeguard against potential breaches and maintain system integrity.
