Hackers exploit critical unauthenticated Atlassian flaw after public PoC

Summary
Attackers began probing CVE-2026-21589 within hours of a public PoC. The unauthenticated flaw affects eight self-hosted Atlassian products and can expose files; in certain Crowd-integrated setups, credentials could enable Jira administrator access.
Key points
- CVE-2026-21589 is an unauthenticated arbitrary file-access flaw affecting self-hosted Bitbucket, Confluence, Jira and five other Atlassian products.
- Previdian observed exploitation attempts on its honeypots within two hours of watchTowr publishing technical research and a public PoC.
- The flaw allows attackers who know a file’s exact path to retrieve files from the application’s web root.
- In certain Crowd-integrated deployments, exposed plaintext credentials could be used to create a Jira administrator account, if Crowd is reachable and permissions allow.
- Atlassian urged administrators to install available security updates; suggested mitigations include restricting external access and applying WAF, proxy or URL-rewrite rules.
- watchTowr released a scanner to help administrators check whether their instances are vulnerable.
Article Details
- Vulnerability Types
- Arbitrary file access
- Directory traversal
- Severity
- Critical
- Exploitation Status
- active
- Exploit Availability
- public_poc
- Patch Status
- available
- Workarounds
- Restrict external network access to affected instances.
- Block the specified traversal patterns with a web application firewall or proxy rule.
- Use Tomcat RewriteValve rules for Confluence, JSM, Jira, Bamboo, and Crowd.
- Use a URL rewrite rule for Bitbucket.
- Limit the IP addresses allowed to reach Crowd; researchers said this would make exploitation significantly more difficult.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 146[.]70[.]187[.]234 | IP address Previdian observed attempting to exploit CVE-2026-21589. |
| IPV4 | 159[.]26[.]119[.]225 | IP address Previdian observed attempting to exploit CVE-2026-21589. |
| IPV4 | 38[.]60[.]157[.]86 | IP address Previdian observed attempting to exploit CVE-2026-21589. |
MITRE ATT&CK
T1190 · Exploit Public-Facing ApplicationPrevidian observed unauthenticated attempts to exploit the file-access flaw in exposed Atlassian applications.T1552.001 · Credentials In FileswatchTowR researchers demonstrated that the flaw could expose plaintext application credentials in WEB-INF/classes/crowd.properties in Crowd-integrated Jira deployments.
CVE
People
Vendors
Products
Bamboo Data CenterBamboo Data CenterBitbucket Data CenterBitbucket Data CenterConfluence Data CenterConfluence Data CenterCrowd Data CenterCrowd Data CenterCrucibleCrucibleFisheyeFisheyeJira Service Management Data CenterJira Service Management Data CenterJira Software Data CenterJira Software Data Center