Last updated: October 7, 2026 at 2:03 PM UTC
All 903 Vulnerability 367 Breach 144 Threat 385 Defense 7
Tag: jira (1 article)Clear

Actively exploited Atlassian flaw lets unauthenticated attackers read protected files across eight Data Center products

Atlassian disclosed CVE-2026-21589, a path traversal flaw rated 9.3 that lets an attacker with no login access read specific files in each product's web application root directory when the exact path is known. It affects the Data Center editions of Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye. After watchTowr published a proof of concept, security firm Previdian observed exploitation attempts against its honeypots within two hours. In Crowd-integrated Jira deployments, attackers extract plaintext credentials from configuration files and use Crowd's API to create administrator accounts, taking full control of the instance.

Check
Inventory self-hosted Atlassian Data Center products, apply the fixed version for each product immediately, and review Crowd-integrated deployments for rogue administrator accounts and stolen credentials.
Affected
Affected Atlassian Data Center products let an unauthenticated attacker read protected application files, and in Crowd-integrated Jira that exposes plaintext credentials used to forge administrator accounts.
Fix
Upgrade each affected product to its fixed release, rotate credentials stored in configuration files, audit administrator accounts and Crowd API activity, and restrict internet exposure.