Skip to content

Security3 publishersIndependently confirmed2 min readPublished

Attackers hit Atlassian's CVE-2026-21589 two hours after watchTowr published the technique

Previdian recorded exploitation attempts against Atlassian's CVE-2026-21589 within two hours of watchTowr publishing the arbitrary file access technique. The CVSS 9.3 flaw lets an unauthenticated attacker read specific webroot files across eight Data Center products.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying Attackers hit Atlassian's CVE-2026-21589 two hours after watchTowr published the technique
Photo: thehackernews.com

What happened

  • Previdian counted 15 exploitation attempts from three IP addresses based in Japan and the United States hitting its honeypot network.
  • On Crowd and Jira an attacker can read crowd.properties, reuse the stored credentials for admin access, and elevate a rogue account to Jira Administrator.
  • Atlassian patched its Cloud products and released fixed Data Center versions for every affected product.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision A maintenance-window cadence does not fit this bug. The first attempts landed two hours after the write-up, before most teams would have read the advisory.
  • capability A Nuclei template, Previdian says, would let scanners test the whole internet for the flaw, moving it from targeted use to mass automated scanning.
  • exposure The flaw is unauthenticated and needs a single request, so any affected instance reachable from the internet is in scope.
  • constraint The attacker must know a file's exact name and path and cannot list directories, but watchTowr published the path to Crowd's credential file, blunting that limit.

It takes one request. watchTowr described a GET to Atlassian's /download/resources path that chains the colorpicker plugin resource with an encoded traversal string, and the trailing slash on the plugin resource lets an unauthenticated caller walk out of the webroot and read a file such as WEB-INF/web.xml [11]. The read pulls tokens, credentials, keys, or other authentication material, according to watchTowr [9].

On Crowd and Jira the payoff is larger. The same read reaches WEB-INF/classes/crowd.properties, which stores Crowd credentials [12]. With those, watchTowr showed, an attacker can log in with administrative access, create users, change privileges, and promote a new rogue account to Jira Administrator [12].

Atlassian stressed a limit. "Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents," the company said [2]. That limit matters less now that the path to the credential file is published [9].

Previdian puts the first attempts two hours after watchTowr's write-up [8]. "Within two hours of public exploit details becoming available, we were already seeing exploitation attempts hit our honeypot network," Previdian founder and CEO Ryan Dewhurst said [13]. The 15 attempts came from three addresses: 38.60.157[.]86, 146.70.187[.]234, and 159.26.119[.]225 [15].

Dewhurst expects the pace to rise. "The release of a Nuclei template will make mass automated scanning even easier, so we expect activity around CVE-2026-21589 to increase quickly. Organizations running affected Atlassian products should treat patching as an immediate priority," he said [14].

Atlassian said its Cloud products are already fixed and shipped Data Center releases for every affected product, including Bitbucket 9.4.26, 10.2.8 and 10.5.1 and Confluence 9.2.26 and 10.2.19 [3]. For teams that cannot patch at once, Atlassian recommends pulling instances off the public internet, applying a WAF rule, blocking requests with Tomcat's RewriteValve for Confluence, JSM, Jira, Bamboo and Crowd, and adding a urlrewrite.xml rule for Bitbucket [4].

What to watch

  • Publication of a public Nuclei template, which would turn targeted attempts into internet-wide scanning.
  • Any confirmed intrusions using Crowd credentials pulled from crowd.properties on Crowd or Jira.
  • Whether the three logged IP addresses expand into a broader set as more scanners pick up the bug.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories