Critical Path Traversal in Atlassian Data Center Products (CVE-2026-21589)
An unauthenticated arbitrary file read vulnerability (CVE-2026-21589) in multiple Atlassian Data Center products allows attackers to access sensitive configuration files via a path traversal flaw in the webresource router.
CVE search metadata
CVE search record: CVE-2026-21589. EPSS: 0.74%. KEV: no. Product: Bitbucket Data Center (< 9.4.26, 10.2.8, 10.5.1), Confluence Data Center (< 9.2.26, 10.2.19), Jira Software Data Center (< 9.12.40, 10.3.26, 11.3.12), Jira Service Management Data Center (< 5.12.40, 10.3.26, 11.3.12), Bamboo Data Center (< 10.2.24, 12.1.12), Crowd Data Center (< 6.3.7, 7.0.3, 7.1.7, 7.2.4), Crucible (< 4.9.15), Fisheye (< 4.9.15), Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, Fisheye. Brief: Critical Path Traversal in Atlassian Data Center Products (CVE-2026-21589). Brief link: https://feed.craftedsignal.io/briefs/2026-10-atlassian-path-traversal/
What's new
- 1. new product Oct 7, 10:33 via cert-eu
CVE-2026-21589 is a critical vulnerability affecting a wide range of self-hosted Atlassian Data Center products, including Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye. The vulnerability arises from improper input validation within the /download/* webresource router. Specifically, the router performs a double URL-decode and utilizes an unescaping mechanism that converts :: sequences into / characters. This behavior bypasses Tomcat's URI normalization, allowing unauthenticated attackers to perform path traversal and read arbitrary files relative to the web application root.
By targeting the WEB-INF/ directory, attackers can extract sensitive files such as web.xml, urlrewrite.xml, and other configuration artifacts that may contain JDBC URLs, API tokens, and private keys. While directory listing is not possible, the predictability of Atlassian application file structures makes this vulnerability highly actionable. Active scanning and proof-of-concept exploits have been observed in the wild shortly after disclosure by watchTowr Labs.
Attack Chain
- Attacker sends a specially crafted GET request to the
/download/resources/endpoint. - The path includes a double URL-encoded traversal sequence (e.g.,
..%3a%3a) designed to survive initial Tomcat normalization. - The webresource router performs a secondary URL-decode on the URI.
- The router's
unescapeSlashesfunction converts the::sequence into a/path separator. - The application constructs a final path, resulting in a traversal sequence like
../../WEB-INF/web.xml. - The
ServletContext.getResourceAsStreamfunction resolves the path relative to the application root without further security gating. - The application returns the contents of the requested sensitive configuration file in the HTTP response body.
- Attacker harvests credentials or application metadata from the returned file for subsequent lateral movement.
Impact
The vulnerability allows unauthenticated information disclosure of highly sensitive configuration data. Successful exploitation provides attackers with the necessary building blocks - such as database credentials and API keys - to compromise the underlying server infrastructure, escalate privileges, or facilitate lateral movement within the network. Multiple self-hosted product lines are affected, and active exploitation has been confirmed following the release of public exploit tooling.
Recommendation
Prioritized actions for detection and mitigation:
- Upgrade all affected Atlassian Data Center and Server products to the fixed versions specified in the Atlassian September 2026 security advisory immediately.
- Implement a WAF or reverse-proxy rule to block all incoming requests containing
%3a%3aor::character sequences in the URL path. - Deploy the specific Tomcat RewriteValve or
urlrewrite.xmlmitigation rules provided by Atlassian for instances where immediate patching is not feasible. - Audit web server access logs for anomalous GET requests targeting the
/download/resources/endpoint with traversal patterns containing..%3a%3aor..::.
Immediate actions
Patch all Atlassian products to the specified safe versions.
Block '%3a%3a' and '::' patterns in WAF.
Threat Hunt
Search for HTTP GET requests containing '..%3a%3a' or '..::' targeting the /download/resources/ endpoint.
Data: webserver_logs
Mitigations
Deploy Tomcat RewriteValve or urlrewrite.xml configuration changes.
CVE-2026-21589
Detection coverage 1
Detect CVE-2026-21589 Exploitation - Path Traversal in Webresource Router
criticalDetects exploitation attempts of CVE-2026-21589 by monitoring for double-encoded path traversal sequences targeting the Atlassian webresource router.
Detection queries are available on the platform. Get full rules →