Atlassian published an advisory on October 5 for CVE-2026-21589, an unauthenticated file read in eight of its Data Center products. Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. Every version before the fix. Atlassian scored it 9.3 on CVSS 4.0 and told customers who can't patch to take the instance off the internet.

The bug is one library. watchTowr diffed the patch and found it in atlassian-plugins-webresource, the shared code that serves plugin assets like icons and stylesheets. Version 6.0.7 is vulnerable. Version 6.0.8 is fixed. Every product above bundles it, which is why one CVE covers eight products.

Two colons beat the slash filter

The router in that library has a pair of helpers called escapeSlashes and unescapeSlashes. They turn a forward slash into a double colon and back again. The traversal filters run on slashes. The conversion back to slashes runs after the filters. So a request path that contains ..::..::..::WEB-INF::web.xml walks past every check and comes out the other side as a normal directory traversal.

watchTowr's write-up on October 6 shows the request against Jira:

GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml

That returns the Tomcat deployment descriptor. Confluence has an equivalent route. Bitbucket blocks web.xml, so the example there pulls urlrewrite.xml instead. The read stays inside the Tomcat web application context. You can't reach /etc/passwd or the database. You can reach anything the app ships in its own webroot, and you need to know the exact path, because the bug doesn't list directories.

Atlassian's advisory leans on that limitation. "Exploitation requires prior knowledge of the target file's exact name and path." True. It is also not much of a limitation, because every Jira install on earth has the same layout and the same file names. Imperva made the same point in its analysis. Predictable directory structure is the whole product.

From one file to Jira administrator

A file read is not code execution, and most of the coverage stops there. watchTowr kept going. They stood up Crowd next to Jira, the way a lot of shops run central auth, and pulled WEB-INF/classes/crowd.properties through the same route. That file holds the Crowd application name and password in plaintext.

With those credentials they called Crowd's REST API, created a user, and added it to jira-administrators. Jira trusts Crowd. Jira admin. The whole chain is unauthenticated HTTP requests against two services that were working as designed. watchTowr notes a Crowd IP allowlist would have blocked the second half, which is a good reminder that the allowlist feature exists and that almost nobody turns it on.

The same shape applies anywhere the webroot holds a secret. Database passwords in a config file, an OAuth client secret, a keystore. Atlassian's own wording is "in some configurations, there may be sensitive files present that increase your risk." Crowd is one of those configurations, and it is a common one.

Two hours from write-up to honeypot

Previdian runs a honeypot network. Ryan Dewhurst, its CEO, told BleepingComputer the first exploitation attempts landed within two hours of watchTowr's post going up on October 6. By October 7 a Nuclei template was public. By October 8 Previdian's tracker showed 158 attempts from 26 IP addresses in eight countries. The early traffic was fingerprinting and sweeps for the usual config files. Jake Knott at watchTowr said nobody had been seen using harvested credentials yet.

Two hours is the number to sit with. Atlassian's advisory went out Monday. The technical details went out Tuesday. Scanners were hitting honeypots Tuesday afternoon. If your Jira is reachable from the internet and you read the advisory on Wednesday morning, the scanners got there before you did. The patch window for a bug like this is now measured in hours, and most change control processes are measured in weeks.

CISA hadn't added it to the Known Exploited Vulnerabilities list as of Wednesday. Don't wait for that. Honeypot hits from 26 addresses is exploitation in the wild by any definition a sysadmin cares about.

What to do if you run Data Center

Patch. The fixed versions are in the advisory, and the ones most people will need are Jira 9.12.40, 10.3.26 or 11.3.12, Confluence 9.2.26 or 10.2.19, and Bitbucket 9.4.26, 10.2.8 or 10.5.1. Atlassian no longer ships binary patches, so this is a full version upgrade on each node. Plan the downtime.

If you can't upgrade today, Atlassian gives four fallbacks, in this order:

  1. Pull the instance off the public internet. The advisory says instances that require login should still be restricted, because the bug doesn't care about login.
  2. Add a WAF or reverse proxy rule that blocks any request containing .. next to a slash, backslash or double colon, including the URL-encoded forms. Atlassian publishes the regex.
  3. For Jira, Confluence, Bamboo and Crowd, enable Tomcat's RewriteValve and install the rewrite.config rules on every node. This needs a restart per node.
  4. For Bitbucket, add the published rule to the top of urlrewrite.xml, on every node and every mirror, then restart.

Then check your logs. Atlassian's guidance is to URL-decode each request line up to two times and search for .. adjacent to /, \ or ::. If you find hits, assume the webroot has been read and rotate what lives there. Crowd application passwords first. watchTowr also published a detection script on GitHub that tests a Jira, Confluence or Bitbucket instance without reading anything sensitive.

Atlassian Cloud customers have nothing to do. Atlassian patched Cloud before the advisory went out and says it found no exploitation there. That gap is the part of this story I expect Atlassian is happiest about. Server licenses ended in February 2024, Data Center is the only way left to run Atlassian on your own hardware, and every Data Center customer just got a reminder of what the vendor's own hosting gets you that yours doesn't. Cloud got the fix before anyone knew there was a bug. You got a Monday advisory, a Tuesday exploit, and a Nuclei template by Wednesday.

I run things on my own hardware on purpose, and I'd make the same choice again. But the price of that choice is a patch cadence that keeps up with watchTowr, and this week it meant a Jira upgrade on a Tuesday for anyone with a public instance, because the alternative was a stranger reading the Crowd password. The next shared library bug in this stack will land the same way. Budget for it.