Attackers started scanning the systems vulnerable to the Atlassian flaw several hours after the researchers published the technical details and proof-of-concept code. Assigned the identifier CVE-2026-21589, the vulnerability impacts several self-hosted Data Center products and could allow unauthorized access to the credentials in some circumstances.
The problem was disclosed by Atlassian on October 5, 2026, with a CVSS score of 9.3. The products affected by the bug are Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. The company already released fixes for all software versions.
The flaw allows the adversaries to access some files in the application root directory without providing proper authentication.
However, it is only possible if the attacker knows the exact name and location of the file because the vulnerability does not allow listing the contents of a directory. Therefore, the attack surface is limited, but there is still a potential risk if the adversary somehow manages to guess the file location.
The security researchers from WatchTowr posted the proof-of-concept code and technical details of the discovered flaw on October 6, 2026.
They managed to identify the origin of the issue – a popular library used in all Atlassian products mentioned above. More importantly, they found out that the vulnerability could be chained to get access to the configuration file with Crowd application credentials in some circumstances.
According to WatchTowr, Crowd is Atlassian’s identity management system, and the mentioned scenario involves Jira Software connected to it.
In this case, the attacker could use the credentials to create a new administrative account and assign it to the Jira administration group. As a result, the adversary would be able to attain full privileged access to the targeted Jira Software instance.
In addition, the security company showed how the proof-of-concept code could be used to take over a victim’s account in case of success. Moreover, the researcher added that the attacks are not random, but rather targeted.
Several hours after the publication of the results, the exploitation framework started scanning corporate websites to find the instances of the affected applications.
On October 8, 2026, Previdian, the exploitation intelligence company, counted 190 attempts from 32 IP addresses in 10 countries. Although the United States Cybersecurity and Infrastructure Agency (CISA) has not included the vulnerability in the Known Exploited Vulnerabilities list, the attacks indicate that the problem needs urgent attention.
The companies using Atlassian’s products should make sure that the affected applications are updated to the latest versions. Those who are not able to do it right away should take the vulnerable instances of the software offline or follow the recommendations stated by Atlassian. In particular, the company suggests deploying the blocking rules to the firewalls or using the Web Server rewrite rules.
In addition, the organizations with Jira Software and Crowd should make sure that the mentioned applications are not at risk of compromise as well.
As seen from the recent incident, the response to the exposure of the flaw may take too long. Moreover, the attacks are often launched right after the proof-of-concept code is published. Therefore, it is critical to apply the necessary security updates as soon as possible.
Read the original article:
