Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions.

The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye.

"This arbitrary file access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions," the Australian company said.

"Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be sensitive files present that increase your risk."

Atlassian said impacted Atlassian Cloud products have been patched, adding that fixes are available for the following products -

  • Bitbucket Data Center - 9.4.26, 10.2.8, and 10.5.1
  • Confluence Data Center - 9.2.26 and 10.2.19
  • Jira Service Management Data Center - 5.12.40, 10.3.26, and 11.3.12
  • Jira Software Data Center - 9.12.40, 10.3.26, and 11.3.12
  • Bamboo Data Center - 10.2.24 and 12.1.12
  • Crowd Data Center - 6.3.7, 7.0.3, 7.1.7, and 7.2.4
  • Crucible - 4.9.15
  • Fisheye - 4.9.15

As temporary mitigation, Atlassian is recommending that customers remove their instance from the public internet, apply a Web Application Firewall (WAF) rule, block requests using Tomcat's RewriteValve (for Confluence, JSM, Jira, Bamboo, and Crowd), and add a new rule to urlrewrite.xml (for Bitbucket).

According to telemetry data from Previdian, a total of 15 exploitation attempts have been detected from three unique IP addresses located in Japan and the U.S. -

  • 38.60.157[.]86
  • 146.70.187[.]234
  • 159.26.119[.]225

The exploitation activity targeting its honeypot network is said to have begun two hours after watchTowr released additional technical details of the vulnerability, stating it allows unauthenticated attackers to retrieve sensitive files within the webroot directory through a single request and extract tokens, credentials, keys, or other authentication material.

According to the preemptive exposure management firm, the underlying vulnerability has to do with Atlassian's web-resource handling, which converts a string like "..::..::..::..::WEB-INF::web.xml" to "../../../../WEB-INF/web.xml." 

As a result, an unauthenticated attacker with knowledge of the resource-resolution logic can abuse this path resolution logic and combine it with an Atlassian "/includes/jquery/plugins/colorpicker/images/" plugin resource by taking advantage of the trailing "/" to reach other files (e.g., "WEB-INF/web.xml") elsewhere in the application -

GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml HTTP/1.1

Host: {{Jira-Hostname}}

Importantly, in the case of Atlassian Crowd and Jira, the attacker could exploit the flaw to access "WEB-INF/classes/crowd.properties," which stores Crowd credentials, and then use them to gain administrative access to the application. Armed with this privileged access, it's possible to create new users, modify user privileges, and elevate a newly created rogue user to Jira Administrator.

"Within two hours of public exploit details becoming available, we were already seeing exploitation attempts hit our honeypot network," Previdian Founder and CEO Ryan Dewhurst said in a statement shared with The Hacker News.

"The release of a Nuclei template will make mass automated scanning even easier, so we expect activity around CVE-2026-21589 to increase quickly. Organizations running affected Atlassian products should treat patching as an immediate priority."

进一步分析

免费工具,针对本文主题进一步深挖分析:

source: TheHackerNews