Threat reportVulnerabilityTL-2026-2966

Atlassian Data Center critical unauthenticated arbitrary file access vulnerability (CVE-2026-21589) across Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible and Fisheye

criticalACTIVE

Atlassian Data Center critical unauthenticated arbitrary (TL-2026-2966) is a critical-severity software vulnerability scored CVSS 9.3, first published 2026-10-06 and last reviewed 2026-10-10. It has no confirmed attribution, affects Atlassian Bitbucket Data Center, references 1 CVE (CVE-2026-21589), maps to 14 MITRE ATT&CK techniques (T1005, T1078, T1083), and is covered by 9 detection rules and 46 indicators of compromise.

CVSS
9.3/10Critical
CVEs
1Referenced vulnerabilities
Techniques
14MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
46Indicators of compromise

Key facts for TL-2026-2966

Threat ID
TL-2026-2966
Severity
CRITICAL
CVSS
9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, software-development, finance, government administration, enterprise
Target regions
Global
Detection rules
9
Indicators of compromise
46
Updates
2026-10-10 · 8 updates · revalidated 8× · latest source

How Atlassian Data Center critical unauthenticated arbitrary works

Atlassian disclosed CVE-2026-21589 (CVSS 4.0 score 9.3), an unauthenticated arbitrary file access flaw that lets a remote attacker read files within the web application root of eight Data Center / self-managed products. No in-the-wild exploitation, public PoC or CISA KEV listing was reported at disclosure; Atlassian Cloud was patched before disclosure.

CVE-2026-21589 is an arbitrary file access (path traversal class) vulnerability affecting Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. Atlassian's advisory (published 2026-10-05) states that an unauthenticated attacker can access specific files within the web application root directory. Exploitation requires prior knowledge of the target file's exact name and path; the flaw provides no directory listing or enumeration capability, which limits blind exploitation but does not help if the attacker targets well-known product file paths.

The CVSS v4.0 vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H (9.3 Critical): network reachable, low complexity, no privileges, no user interaction, high confidentiality impact on the vulnerable system and high impact on subsequent systems. Atlassian did not assign a CWE in its advisory or the CVE record; secondary analysis (The Hacker News, The CyberSec Guru) classifies it as CWE-22 path traversal, which is an analyst assessment rather than a vendor statement. Atlassian states all versions of the listed products are affected until upgraded to the fixed releases. Atlassian Cloud instances were already patched before disclosure and Atlassian reports no evidence of active exploitation; it also states it cannot confirm whether any given customer instance was affected.

Because the mitigation logic blocks requests with '..' adjacent to '/', '\' or '::' (including URL-encoded forms up to two levels), the exploitation pattern is traversal sequences in the request path. Secondary reporting notes that the files potentially exposed on such platforms include configuration files, credentials/API keys, database connection strings and CI/CD definitions; this is a risk characterization from the reporting, not a confirmed exploited outcome. Reporting also draws a parallel with CVE-2021-26086 (a Jira path traversal added to CISA KEV on 2024-11-12), suggesting these products are historically attractive targets once details circulate.

Atlassian published three temporary mitigations (not a substitute for patching): (1) a WAF / reverse-proxy rule for all eight products, (2) a Tomcat RewriteValve configuration for Confluence, Jira Software, Jira Service Management, Bamboo and Crowd (restart required, every cluster node), and (3) urlrewrite.xml rules for Bitbucket (every node, mirror and mirror farm node). Defenders can hunt historical access logs by URL-decoding requests (up to twice) and searching for '..' adjacent to path separators, or by running the block pattern against raw log lines. Instances that cannot be patched or mitigated should be taken offline.

MITRE ATT&CK techniques used in TL-2026-2966

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Discovery

T1083 File and Directory Discovery

Persistence

T1098 Account Manipulation; T1136 Create Account

Credential Access

T1552 Unsecured Credentials; T1552.001 Unsecured Credentials: Credentials In Files

Resource Development

T1583.003 Acquire Infrastructure; T1588.005 Obtain Capabilities: Exploits

Reconnaissance

T1592 Gather Victim Host Information; T1592.002 Gather Victim Host Information; T1595.002 Vulnerability Scanning

Affected products and versions in Atlassian Data Center critical unauthenticated arbitrary

  • Atlassian — Bitbucket Data Center
    Vulnerable versions: All versions prior to fixed releases
    Fixed in: 9.4.26; 10.2.8; 10.5.1
  • Atlassian — Confluence Data Center
    Vulnerable versions: All versions prior to fixed releases
    Fixed in: 9.2.26; 10.2.19
  • Atlassian — Jira Software Data Center
    Vulnerable versions: All versions prior to fixed releases
    Fixed in: 9.12.40; 10.3.26; 11.3.12
  • Atlassian — Jira Service Management Data Center
    Vulnerable versions: All versions prior to fixed releases
    Fixed in: 5.12.40; 10.3.26; 11.3.12
  • Atlassian — Bamboo Data Center
    Vulnerable versions: All versions prior to fixed releases
    Fixed in: 10.2.24; 12.1.12
  • Atlassian — Crowd Data Center
    Vulnerable versions: All versions prior to fixed releases
    Fixed in: 6.3.7; 7.0.3; 7.1.7; 7.2.4
  • Atlassian — Crucible
    Vulnerable versions: All versions prior to fixed release
    Fixed in: 4.9.15
  • Atlassian — Fisheye
    Vulnerable versions: All versions prior to fixed release
    Fixed in: 4.9.15

Remediation for Atlassian Data Center critical unauthenticated arbitrary

Patches

  • Bitbucket Data Center: 9.4.26, 10.2.8 or 10.5.1
  • Confluence Data Center: 9.2.26 or 10.2.19
  • Jira Software Data Center: 9.12.40, 10.3.26 or 11.3.12
  • Jira Service Management Data Center: 5.12.40, 10.3.26 or 11.3.12
  • Bamboo Data Center: 10.2.24 or 12.1.12
  • Crowd Data Center: 6.3.7, 7.0.3, 7.1.7 or 7.2.4
  • Crucible and Fisheye: 4.9.15

Immediate actions

  • Upgrade every affected Data Center / self-managed instance to a fixed release (or take it offline if it cannot be patched or mitigated)
  • Apply Atlassian's temporary mitigation as a stopgap: WAF/reverse-proxy rule blocking '..' adjacent to '/', '\' or '::' (raw and URL-encoded up to two levels)
  • Hunt historical access logs: URL-decode requests (up to twice) and search for '..' next to path separators; run the Atlassian block pattern against raw log lines
  • Treat any hit on traversal patterns against these products as a potential credential/config disclosure and rotate exposed secrets

Workarounds

  • WAF / reverse proxy blocking rule (all eight products)
  • Tomcat RewriteValve configuration on every node (Confluence, Jira Software, Jira Service Management, Bamboo, Crowd; restart required)
  • urlrewrite.xml rules on every node, mirror and mirror farm node (Bitbucket; restart required)

Longer-term hardening

  • Keep Atlassian Data Center products off the direct internet; front them with a reverse proxy/WAF with path-normalization rules
  • Minimize secrets stored under the web application root and in files readable by the application service account
  • Monitor CISA KEV and Atlassian advisories for status change in exploitation

CVEs associated with Atlassian Data Center critical unauthenticated arbitrary

CVE-2026-21589

Weaknesses (CWE) in Atlassian Data Center critical unauthenticated arbitrary

CWE-22, CWE-552, CWE-200, CWE-284

Timeline of Atlassian Data Center critical unauthenticated arbitrary

Showing the 20 most recent tracked events.

  • Atlassian publishes the security advisory for CVE-2026-21589 covering Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye
  • Atlassian reports its Cloud instances were patched before public disclosure with no evidence of exploitation
  • SANS ISC honeypots begin recording CVE-2026-21589 exploit attempts for WEB-INF files (web.xml, urlrewrite.xml) from 13 Digital Ocean-associated IPs, believed to be a single actor, one day after the patch.
  • watchTowr Intel FAQ states active exploitation was confirmed as of this date; Atlassian, Rapid7 and SecurityWeek report no confirmed exploitation (contested).
  • watchTowr Labs publishes a root-cause analysis (atlassian-plugins-webresource '::' traversal, library 6.0.7 and earlier) and a public detection/file-read PoC on GitHub.
  • Atlassian publishes an FAQ; watchTowr reports no exploitation in the wild as of this date and recommends log review for traversal patterns
  • NVD record last modified with CWE-552 mapping; CVE not in CISA KEV (status: Awaiting Analysis)
  • Help Net Security, The Hacker News and others report the flaw; Atlassian states no evidence of active exploitation, and no public PoC or KEV listing is reported
  • Previdian later cites 158 exploitation attempts from 26 IPs in eight countries as of October 7.
  • Rapid7 vulnerability checks for CVE-2026-21589 become available (7-8 October).
  • VulnCheck adds CVE-2026-21589 to its KEV list; CISA KEV listing was still not reported.
  • Previdian reports 15 exploitation attempts from three IPs (Japan and US) against its honeypot network about two hours after watchTowr's technical details and checker script went public; no threat actor attributed.
  • SANS ISC publishes the diary 'Scans for Atlassian vulnerability (CVE-2026-21589)' with the observed attack paths and source IPs.
  • Akamai publishes research and Adaptive Security Engine rule 3000990 v1; Rapid7 and SecurityWeek note no CISA KEV listing.
  • SecurityOnline reports a public Nuclei template and Previdian Cyber honeypot sightings of exploitation attempts (IPs not published).
  • Previdian telemetry shows peak exploitation activity on October 7-8 at roughly 107-108 attempts per day.
  • Infosecurity Magazine, BleepingComputer, Help Net Security and Xcitium report active exploitation, citing Bamboo Data Center as a confirmed target.
  • CVE-2026-21589 still reported as not listed in the CISA Known Exploited Vulnerabilities catalog.
  • SecurityWeek reports Previdian has observed 190 exploitation attempts from 32 IP addresses across 10 countries; no threat actor attributed.
  • Previdian telemetry totals 355 attempts from 50 unique IPs in 17 countries across four sensors; last activity observed October 10. Activity is mostly fingerprinting and config-file harvesting; no post-compromise activity or actor attribution reported.

Update history for TL-2026-2966

Sources cited for Atlassian Data Center critical unauthenticated arbitrary

Detection coverage for TL-2026-2966

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2966 across Splunk SPL, Microsoft KQL and Sigma, covering 46 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
46 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats