Published: Wed 07 October 2026
Prepared by: Adam Skupien, Vulnerability Security Analyst
Atlassian has released an advisory for CVE-2026-21589, a critical (CVSS 9.3) unauthenticated file read vulnerability affecting all Atlassian Data Center products: Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible and Fisheye. A patch is available, and we urge organisations to apply it as soon as possible, ahead of their normal patch cycle. Atlassian Cloud is not affected.
An unauthenticated attacker can read files within the application web root, including WEB-INF configuration files. Atlassian notes the attacker must know the exact file path, but the locations of sensitive configuration files are documented in Atlassian's public product documentation, so this is not a meaningful barrier. Directory listing is not possible.
All versions prior to the fixed releases below of:
Sensitive configuration files may be exposed, and watchTowr Labs has demonstrated this can lead to full compromise. For example, Jira instances integrated with Crowd store the Crowd application credentials in plaintext in WEB-INF/classes/crowd.properties. An attacker who obtains them can create users and grant administrator access, unless Crowd access is restricted by IP allowlist.
.. adjacent to /, \ or ::.WEB-INF configuration files (for example Crowd application credentials) on instances that were internet-facing and unpatched. Treat this as urgent if log review finds matching requests.Full instructions and rule syntax are in the Atlassian advisory.
.. adjacent to /, \ or :: (URL-decode up to two passes first).Optional: if you cannot easily confirm your versions, watchTowr Labs has published a detection tool for Jira, Confluence and Bitbucket. It is third-party code that sends requests to the target, so review it first and run it only against systems you own
MDR customers: Triskele Labs will continue tuning detections and analysing IOCs, as they become publicly available, for behaviours consistent with the exploitation of CVE-2026-21589 across supported log sources.
Vulnerability Management customers: Environments will be assessed for vulnerable versions of the Atlassian Data Center products affected by CVE-2026-21589. Any findings will be communicated through priority channels.