Protect.Computer
NEWS

Atlassian CVE-2026-21589 Now Exploited After Public PoC

· 1 min read · Network safety Got hacked
Atlassian CVE-2026-21589 Now Exploited After Public PoC

The critical Atlassian file-access flaw we covered yesterday, CVE-2026-21589, is now under attack. Security firm Previdian told BleepingComputer its honeypots saw exploitation attempts within two hours of watchTowr publishing a technical write-up and public proof-of-concept, and a Nuclei scanning template has since appeared. Previdian expects activity to rise sharply in the coming days.

watchTowr traced the bug to a shared web-resource library that turns double colons ("::") into forward slashes, enabling directory-traversal requests through plugin resource endpoints that read protected files without authentication. The researchers could not traverse outside the Tomcat application context, but they showed a worse outcome in Crowd-integrated deployments: reading WEB-INF/classes/crowd.properties exposes plaintext application credentials, which can be used through Crowd’s API to create a Jira administrator account. That requires Crowd to be reachable and the application to have sufficient permissions; limiting Crowd to allowed IP addresses makes it much harder. Previdian listed three source IPs it has seen probing: 38.60.157[.]86, 146.70.187[.]234 and 159.26.119[.]225.

How to check if you’re affected

Affected products are self-hosted Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd Data Center, plus Crucible and Fisheye. Check your installed version against the fixed versions in Atlassian’s advisory and update; our earlier post lists them. If you cannot patch immediately, restrict external network access and apply the WAF/proxy or Tomcat RewriteValve (Bitbucket: URL rewrite) rules in Atlassian’s bulletin. Atlassian says it cannot tell whether individual instances were compromised, so review Jira, Confluence and Crowd for unexpected new administrator accounts and for requests containing “::” path patterns. watchTowr has released a free scanner to test whether an instance is vulnerable.

Sources

Related reading