Atlassian Data Center customers have a live file-read problem. CVE-2026-21589 (CVSS 9.3) lets an unauthenticated attacker read specific files inside the web application root if they already know the exact name and path. Directory listing is not part of the bug. Exploitation attempts hit a honeypot network about two hours after public technical details landed.
What happened
Atlassian disclosed an arbitrary file-access flaw across self-hosted Data Center products. Cloud products were patched by the vendor. Researchers tied the bug to web-resource path handling that rewrites separator strings into directory traversal. A single request can pull files such as WEB-INF/web.xml from the application root.
Previdian reported 15 attempts from three IP addresses in Japan and the United States. On Crowd and Jira, a successful read of crowd.properties can expose Crowd credentials. Those credentials can be used to create users and promote a new account to Jira administrator.
Who is affected
Self-hosted Data Center installs of Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye on unfixed versions. Internet-facing instances are the immediate target. Internal instances still matter if an attacker already has a foothold on the network.
- Bitbucket Data Center fixed in 9.4.26, 10.2.8, and 10.5.1
- Confluence Data Center fixed in 9.2.26 and 10.2.19
- Jira Software and Jira Service Management Data Center fixed in 5.12.40, 10.3.26, and 11.3.12 (JSM) and 9.12.40, 10.3.26, and 11.3.12 (Jira)
- Bamboo, Crowd, Crucible, and Fisheye also have fixed builds
What to do now
Patch the fixed Data Center build today, or take the instance off the public internet until you do. If you cannot patch immediately, apply Atlassian's WAF or Tomcat RewriteValve mitigation and block the known resource path. After patching, review admin user creation, Crowd credential files, and authentication logs for new accounts you did not create.
Source: The Hacker News, 7 October 2026, Atlassian Data Center flaw draws exploitation attempts within two hours.
Also on the blog
- FortiBleed: FBI says 86,644 Fortinet device credentials still in play
- CVE-2026-102255: CVSS 10 SSRF in SonicWall SMA1000
- LunexStealer: 100-plus sites push fake Cloudflare checks
- CVE-2026-91140: Progress DataDirect AI agent command injection
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.