Security researchers have detected active exploitation of a critical Atlassian vulnerability affecting self-hosted Jira, Confluence, and Bitbucket deployments, just hours after detailed technical analysis was published.
The flaw, tracked as CVE-2026-21589, lets unauthenticated attackers read specific files in an application's web root directory if they know the exact file name and path. Security company Previdian detected the activity on its honeypot network hours after offensive security firm watchTowr published a technical report demonstrating exploitation.
Atlassian disclosed the arbitrary file-access vulnerability on Monday and issued a security advisory urging administrators of self-hosted instances to apply updates as soon as possible, noting it cannot determine whether individual customer instances have been compromised. Eight products are affected: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye.
watchTowr's research traces the root cause to a shared web-resource library that converts double colons “::” into forward slashes “/”, enabling directory-traversal requests through plugin resource endpoints. In Crowd-integrated Jira deployments, the researchers demonstrated that attackers could escalate to administrator level by reading plaintext application credentials from WEB-INF/classes/crowd.properties and using them to create a Jira administrator account through Crowd's API.
Crowd provides centralized identity management, single sign-on, and access management for connected Data Center apps. The escalation path depends on Crowd being reachable from the application, and the researchers note that restricting Crowd to a list of allowed IP addresses would make exploitation significantly more difficult.
“[An attacker] would need to pivot through arbitrary machines or use SSRF-like capabilities of Jira, Confluence, or Bitbucket to reach Crowd directly,” the researchers said.
Previdian said the public technical details were sufficient to help threat actors scan for exposed vulnerable instances and probe them for exploitation.