Hackers began exploiting CVE-2026-21589 within hours of a public proof-of-concept dropping on October 6. The vulnerability — a CVSS 9.3 unauthenticated file read — lives in a shared library used across all eight Atlassian Data Center products: Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye. If you run any of them on-premises and haven’t patched, there is a reasonable chance attackers are already reading your config files.
Eight Products, One Vulnerable Library
The root cause is a shared web-resource endpoint — /download/* — present across all affected products. The attack exploits two quirks in how the application processes URLs:
- The encoded sequence
%3a%3a(URL-encoded::) survives Tomcat’s path normalizer because Tomcat only decodes the URI once. - The application then calls
URLDecoder.decode()a second time, followed byRouter.unescapeSlashes(), which converts::into/.
The result is a working ../ traversal primitive inside the application layer. A simple unauthenticated HTTP GET request is all it takes:
GET /jira/download/..%3a%3aWEB-INF/web.xml HTTP/1.1
Host: your-jira.internal
No authentication. No user interaction. No credentials to steal first. The request lands, the double-colon gets unescaped, and the file is returned.
What Attackers Can Actually Read
Atlassian notes that attackers need to know a file’s exact path — there’s no directory listing. That sounds like a meaningful constraint. It is not. Application configuration files follow well-known conventions across Atlassian products, and PoC scripts already target the most useful ones.
Files within reach include WEB-INF/web.xml, servlet configuration files, application property files, and anything placed in the web root during setup or deployment. The worst case is Crowd: its crowd.properties file contains plaintext credentials for the Crowd admin user. An attacker who reads that file can call the Crowd REST API to create new administrator accounts — turning a file read into a full identity system takeover. If Crowd falls, every product integrated with it falls too.
Bitbucket holds source code. Bamboo runs CI/CD pipelines and can expose deploy keys or environment variables accessible from the web root. Confluence holds internal documentation that often includes credentials, API keys, and partner details that teams paste into pages because “it’s internal.” CVE-2026-21589 makes it external.
Patch Now: Version Table
Atlassian released fixed versions for all affected products. Upgrade to at least the minimum fixed version below, or — better — to the latest available release. See the official Atlassian advisory for the full version matrix.
| Product | Fixed Versions |
|---|---|
| Jira Software Data Center | 9.12.40, 10.3.26, 11.3.12 |
| Jira Service Management Data Center | 5.12.40, 10.3.26, 11.3.12 |
| Confluence Data Center | 9.2.26, 10.2.19 |
| Bitbucket Data Center | 9.4.26, 10.2.8, 10.5.1 |
| Bamboo Data Center | 10.2.24, 12.1.12 |
| Crowd Data Center | 6.3.7, 7.0.3, 7.1.7, 7.2.4 |
| Crucible | 4.9.15 |
Atlassian Cloud instances have already been patched. Only self-hosted Data Center deployments need action.
Can’t Patch Today? Mitigate First
If patching is blocked by a change freeze or lengthy upgrade testing, two temporary mitigation paths exist.
WAF or reverse proxy rule: Block HTTP requests whose URL contains .. adjacent to /, \, or ::, including URL-encoded variants (%2e%2e%2f, %2e%2e%5c, %3a%3a). Copy the exact regexes from Atlassian’s advisory — do not write your own from scratch.
Tomcat RewriteValve / urlrewrite.xml: For Confluence, Jira products, Bamboo, and Crowd, configure Tomcat’s RewriteValve with the vendor-supplied rules. For Bitbucket, apply the urlrewrite.xml rule to all cluster nodes, mirrors, and mirror farm nodes.
Atlassian’s position is clear: these workarounds are not a replacement for patching. Apply them while you schedule the upgrade, not instead of it.
How to Check Your Logs
To hunt for exploitation attempts in your access logs, URL-decode each log entry up to twice, then search for .. immediately adjacent to /, \, or ::. The projectdiscovery/nuclei-templates repository has a Nuclei template for CVE-2026-21589 that automates scanning unpatched hosts. Rapid7’s ETR analysis also provides detection guidance and indicators to watch for.
A Pattern Worth Naming
CVE-2026-21589 is Atlassian’s third major critical CVE since 2022. CVE-2022-26134 hit Confluence with a CVSS 9.8 OGNL injection — ransomware operators were inside within days. CVE-2023-22518 broke access controls across Confluence. Now a shared library in eight products has been carrying a traversal primitive that turned critical the moment someone looked closely.
The common thread is self-hosted Atlassian infrastructure and slow patching. A CVSS 9+ advisory from Atlassian should trigger a 24-hour patch window, not a sprint ticket. These tools hold your source code, your deployments, and your team’s identity. Treating them like low-priority SaaS is how you end up in a breach report.













