Threat reportVulnerabilityTL-2026-2966
Atlassian Data Center critical unauthenticated arbitrary file access vulnerability (CVE-2026-21589) across Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible and Fisheye
Atlassian Data Center critical unauthenticated arbitrary (TL-2026-2966) is a critical-severity software vulnerability scored CVSS 9.3, first published 2026-10-06 and last reviewed 2026-10-10. It has no confirmed attribution, affects Atlassian Bitbucket Data Center, references 1 CVE (CVE-2026-21589), maps to 14 MITRE ATT&CK techniques (T1005, T1078, T1083), and is covered by 9 detection rules and 46 indicators of compromise.
- CVSS
- 9.3/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 46Indicators of compromise
Key facts for TL-2026-2966
- Threat ID
- TL-2026-2966
- Severity
- CRITICAL
- CVSS
- 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, software-development, finance, government administration, enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 46
- Updates
- 2026-10-10 · 8 updates · revalidated 8× · latest source
How Atlassian Data Center critical unauthenticated arbitrary works
Atlassian disclosed CVE-2026-21589 (CVSS 4.0 score 9.3), an unauthenticated arbitrary file access flaw that lets a remote attacker read files within the web application root of eight Data Center / self-managed products. No in-the-wild exploitation, public PoC or CISA KEV listing was reported at disclosure; Atlassian Cloud was patched before disclosure.
CVE-2026-21589 is an arbitrary file access (path traversal class) vulnerability affecting Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. Atlassian's advisory (published 2026-10-05) states that an unauthenticated attacker can access specific files within the web application root directory. Exploitation requires prior knowledge of the target file's exact name and path; the flaw provides no directory listing or enumeration capability, which limits blind exploitation but does not help if the attacker targets well-known product file paths.
The CVSS v4.0 vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H (9.3 Critical): network reachable, low complexity, no privileges, no user interaction, high confidentiality impact on the vulnerable system and high impact on subsequent systems. Atlassian did not assign a CWE in its advisory or the CVE record; secondary analysis (The Hacker News, The CyberSec Guru) classifies it as CWE-22 path traversal, which is an analyst assessment rather than a vendor statement. Atlassian states all versions of the listed products are affected until upgraded to the fixed releases. Atlassian Cloud instances were already patched before disclosure and Atlassian reports no evidence of active exploitation; it also states it cannot confirm whether any given customer instance was affected.
Because the mitigation logic blocks requests with '..' adjacent to '/', '\' or '::' (including URL-encoded forms up to two levels), the exploitation pattern is traversal sequences in the request path. Secondary reporting notes that the files potentially exposed on such platforms include configuration files, credentials/API keys, database connection strings and CI/CD definitions; this is a risk characterization from the reporting, not a confirmed exploited outcome. Reporting also draws a parallel with CVE-2021-26086 (a Jira path traversal added to CISA KEV on 2024-11-12), suggesting these products are historically attractive targets once details circulate.
Atlassian published three temporary mitigations (not a substitute for patching): (1) a WAF / reverse-proxy rule for all eight products, (2) a Tomcat RewriteValve configuration for Confluence, Jira Software, Jira Service Management, Bamboo and Crowd (restart required, every cluster node), and (3) urlrewrite.xml rules for Bitbucket (every node, mirror and mirror farm node). Defenders can hunt historical access logs by URL-decoding requests (up to twice) and searching for '..' adjacent to path separators, or by running the block pattern against raw log lines. Instances that cannot be patched or mitigated should be taken offline.
MITRE ATT&CK techniques used in TL-2026-2966
Collection
T1005 Data from Local System; T1213 Data from Information Repositories
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Discovery
T1083 File and Directory Discovery
Persistence
T1098 Account Manipulation; T1136 Create Account
Credential Access
T1552 Unsecured Credentials; T1552.001 Unsecured Credentials: Credentials In Files
Resource Development
T1583.003 Acquire Infrastructure; T1588.005 Obtain Capabilities: Exploits
Reconnaissance
T1592 Gather Victim Host Information; T1592.002 Gather Victim Host Information; T1595.002 Vulnerability Scanning
Affected products and versions in Atlassian Data Center critical unauthenticated arbitrary
- Atlassian — Bitbucket Data Center
Vulnerable versions: All versions prior to fixed releases
Fixed in: 9.4.26; 10.2.8; 10.5.1 - Atlassian — Confluence Data Center
Vulnerable versions: All versions prior to fixed releases
Fixed in: 9.2.26; 10.2.19 - Atlassian — Jira Software Data Center
Vulnerable versions: All versions prior to fixed releases
Fixed in: 9.12.40; 10.3.26; 11.3.12 - Atlassian — Jira Service Management Data Center
Vulnerable versions: All versions prior to fixed releases
Fixed in: 5.12.40; 10.3.26; 11.3.12 - Atlassian — Bamboo Data Center
Vulnerable versions: All versions prior to fixed releases
Fixed in: 10.2.24; 12.1.12 - Atlassian — Crowd Data Center
Vulnerable versions: All versions prior to fixed releases
Fixed in: 6.3.7; 7.0.3; 7.1.7; 7.2.4 - Atlassian — Crucible
Vulnerable versions: All versions prior to fixed release
Fixed in: 4.9.15 - Atlassian — Fisheye
Vulnerable versions: All versions prior to fixed release
Fixed in: 4.9.15
Remediation for Atlassian Data Center critical unauthenticated arbitrary
Patches
- Bitbucket Data Center: 9.4.26, 10.2.8 or 10.5.1
- Confluence Data Center: 9.2.26 or 10.2.19
- Jira Software Data Center: 9.12.40, 10.3.26 or 11.3.12
- Jira Service Management Data Center: 5.12.40, 10.3.26 or 11.3.12
- Bamboo Data Center: 10.2.24 or 12.1.12
- Crowd Data Center: 6.3.7, 7.0.3, 7.1.7 or 7.2.4
- Crucible and Fisheye: 4.9.15
Immediate actions
- Upgrade every affected Data Center / self-managed instance to a fixed release (or take it offline if it cannot be patched or mitigated)
- Apply Atlassian's temporary mitigation as a stopgap: WAF/reverse-proxy rule blocking '..' adjacent to '/', '\' or '::' (raw and URL-encoded up to two levels)
- Hunt historical access logs: URL-decode requests (up to twice) and search for '..' next to path separators; run the Atlassian block pattern against raw log lines
- Treat any hit on traversal patterns against these products as a potential credential/config disclosure and rotate exposed secrets
Workarounds
- WAF / reverse proxy blocking rule (all eight products)
- Tomcat RewriteValve configuration on every node (Confluence, Jira Software, Jira Service Management, Bamboo, Crowd; restart required)
- urlrewrite.xml rules on every node, mirror and mirror farm node (Bitbucket; restart required)
Longer-term hardening
- Keep Atlassian Data Center products off the direct internet; front them with a reverse proxy/WAF with path-normalization rules
- Minimize secrets stored under the web application root and in files readable by the application service account
- Monitor CISA KEV and Atlassian advisories for status change in exploitation
CVEs associated with Atlassian Data Center critical unauthenticated arbitrary
Weaknesses (CWE) in Atlassian Data Center critical unauthenticated arbitrary
Timeline of Atlassian Data Center critical unauthenticated arbitrary
Showing the 20 most recent tracked events.
- Atlassian publishes the security advisory for CVE-2026-21589 covering Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye
- Atlassian reports its Cloud instances were patched before public disclosure with no evidence of exploitation
- SANS ISC honeypots begin recording CVE-2026-21589 exploit attempts for WEB-INF files (web.xml, urlrewrite.xml) from 13 Digital Ocean-associated IPs, believed to be a single actor, one day after the patch.
- watchTowr Intel FAQ states active exploitation was confirmed as of this date; Atlassian, Rapid7 and SecurityWeek report no confirmed exploitation (contested).
- watchTowr Labs publishes a root-cause analysis (atlassian-plugins-webresource '::' traversal, library 6.0.7 and earlier) and a public detection/file-read PoC on GitHub.
- Atlassian publishes an FAQ; watchTowr reports no exploitation in the wild as of this date and recommends log review for traversal patterns
- NVD record last modified with CWE-552 mapping; CVE not in CISA KEV (status: Awaiting Analysis)
- Help Net Security, The Hacker News and others report the flaw; Atlassian states no evidence of active exploitation, and no public PoC or KEV listing is reported
- Previdian later cites 158 exploitation attempts from 26 IPs in eight countries as of October 7.
- Rapid7 vulnerability checks for CVE-2026-21589 become available (7-8 October).
- VulnCheck adds CVE-2026-21589 to its KEV list; CISA KEV listing was still not reported.
- Previdian reports 15 exploitation attempts from three IPs (Japan and US) against its honeypot network about two hours after watchTowr's technical details and checker script went public; no threat actor attributed.
- SANS ISC publishes the diary 'Scans for Atlassian vulnerability (CVE-2026-21589)' with the observed attack paths and source IPs.
- Akamai publishes research and Adaptive Security Engine rule 3000990 v1; Rapid7 and SecurityWeek note no CISA KEV listing.
- SecurityOnline reports a public Nuclei template and Previdian Cyber honeypot sightings of exploitation attempts (IPs not published).
- Previdian telemetry shows peak exploitation activity on October 7-8 at roughly 107-108 attempts per day.
- Infosecurity Magazine, BleepingComputer, Help Net Security and Xcitium report active exploitation, citing Bamboo Data Center as a confirmed target.
- CVE-2026-21589 still reported as not listed in the CISA Known Exploited Vulnerabilities catalog.
- SecurityWeek reports Previdian has observed 190 exploitation attempts from 32 IP addresses across 10 countries; no threat actor attributed.
- Previdian telemetry totals 355 attempts from 50 unique IPs in 17 countries across four sensors; last activity observed October 10. Activity is mostly fingerprinting and config-file harvesting; no post-compromise activity or actor attribution reported.
Update history for TL-2026-2966
- 2026-10-10 — Atlassian Data Center Unauthenticated Arbitrary File Access (CVE-2026-21589) Exploited Within Two Hours of Public Details: What changed No field escalation: exploitability (ACTIVE), severity (CRITICAL) and status already reflect the newer report. Exploitation volume grows from 190 attempts / 32 IPs / 10 countries (Oct 8) to 355 attempts / 50 IPs / 17 countries
- 2026-10-10 — CVE-2026-21589 — Critical Unauthenticated Arbitrary File Access in Atlassian Data Center Products (atlassian-plugins-webresource) Exploited in the Wild: What changed No field escalation: severity CRITICAL, exploitability ACTIVE and status ACTIVE are already set. Adds a VulnCheck KEV listing, Bamboo Data Center as a confirmed exploitation target and Rapid7 check availability. New indicators
- 2026-10-09 — Atlassian CVE-2026-21589 Unauthenticated Arbitrary File Access in Eight Data Center Products Exploited Within Hours of PoC Publication: What changed No field escalation: severity CRITICAL, exploitability ACTIVE and status ACTIVE are already set. Exploitation scale updated to 190 attempts from 32 IPs in 10 countries as of 2026-10-08 (previously 15 attempts from 3 IPs). New i
- 2026-10-07 — Exploitation attempts begin against critical Atlassian Data Center arbitrary file access flaw (CVE-2026-21589): What changed No field escalation: severity CRITICAL, exploitability ACTIVE and status ACTIVE already reflect the exploitation reports. New indicators (5) 3 Previdian honeypot source IPs (38.60.157.86, 146.70.187.234, 159.26.119.225), the co
- 2026-10-07 — CVE-2026-21589: Critical Atlassian Data Center Unauthenticated Arbitrary File Access (Path Traversal) Across 8 Products: What changed No field escalation. Existing record (ACTIVE exploitation, SANS ISC honeypot data, public PoC) is more advanced than the newer report, which frames the CVE as THEORETICAL / MONITORING with no known exploitation. New indicators
- 2026-10-07 — Active scanning and exploitation of Atlassian pre-auth arbitrary file read vulnerability (CVE-2026-21589) across Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible and Fisheye Data Center: What changed Exploitability POC_PUBLIC → ACTIVE and status MONITORING → ACTIVE: SANS ISC honeypots independently observed exploit attempts starting 2026-10-06, replacing the earlier contested vendor-vs-watchTowr claims. New indicators (14)
- 2026-10-07 — CVE-2026-21589: Critical Unauthenticated Arbitrary File Read (Path Traversal) in Eight Atlassian Data Center Products: What changed Exploitability THEORETICAL → POC_PUBLIC: watchTowr published a working PoC on GitHub on 2026-10-06 and NVD SSVC records a PoC as available. Severity and CVSS (9.3) unchanged. Existing tags 'no-public-poc' and 'no-known-exploita
- 2026-10-06 — CVE-2026-21589: Critical Atlassian Unauthenticated Arbitrary File Access (Path Traversal) Across Eight Data Center Products: What changed No severity, exploitability or status change; exploitability remains THEORETICAL (no ITW exploitation, no public PoC, not in KEV as of 2026-10-06). New indicators (4) 4 new mitigation/hunting artifacts: Atlassian traversal rege
Sources cited for Atlassian Data Center critical unauthenticated arbitrary
- Atlassian security advisory: CVE-2026-21589 arbitrary file access vulnerability impacts multiple products
- CVE-2026-21589 CVE record
- NVD API record for CVE-2026-21589
- Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589)
- Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
- CVE-2026-21589: Critical Atlassian Flaw Exposes Sensitive Files
- Critical Path Traversal in Atlassian Data Center Exposes Development Infrastructure
- Critical CVE-2026-21589 Vulnerability Exposes Atlassian Data Center Products to Unauthenticated File Disclosure
- Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products
Detection coverage for TL-2026-2966
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2966 across Splunk SPL, Microsoft KQL and Sigma, covering 46 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.