{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/confluence-data-center--9.2.26-10.2.19/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-21589"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Bitbucket Data Center (\u003c 9.4.26, 10.2.8, 10.5.1)","Confluence Data Center (\u003c 9.2.26, 10.2.19)","Jira Software Data Center (\u003c 9.12.40, 10.3.26, 11.3.12)","Jira Service Management Data Center (\u003c 5.12.40, 10.3.26, 11.3.12)","Bamboo Data Center (\u003c 10.2.24, 12.1.12)","Crowd Data Center (\u003c 6.3.7, 7.0.3, 7.1.7, 7.2.4)","Crucible (\u003c 4.9.15)","Fisheye (\u003c 4.9.15)","Bitbucket Data Center","Confluence Data Center","Jira Service Management Data Center","Jira Software Data Center","Bamboo Data Center","Crowd Data Center","Crucible","Fisheye"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","web-application","path-traversal"],"_cs_type":"threat","_cs_vendors":["Atlassian"],"content_html":"\u003cp\u003eCVE-2026-21589 is a critical vulnerability affecting a wide range of self-hosted Atlassian Data Center products, including Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye. The vulnerability arises from improper input validation within the \u003ccode\u003e/download/*\u003c/code\u003e webresource router. Specifically, the router performs a double URL-decode and utilizes an unescaping mechanism that converts \u003ccode\u003e::\u003c/code\u003e sequences into \u003ccode\u003e/\u003c/code\u003e characters. This behavior bypasses Tomcat's URI normalization, allowing unauthenticated attackers to perform path traversal and read arbitrary files relative to the web application root.\u003c/p\u003e\n\u003cp\u003eBy targeting the \u003ccode\u003eWEB-INF/\u003c/code\u003e directory, attackers can extract sensitive files such as \u003ccode\u003eweb.xml\u003c/code\u003e, \u003ccode\u003eurlrewrite.xml\u003c/code\u003e, and other configuration artifacts that may contain JDBC URLs, API tokens, and private keys. While directory listing is not possible, the predictability of Atlassian application file structures makes this vulnerability highly actionable. Active scanning and proof-of-concept exploits have been observed in the wild shortly after disclosure by watchTowr Labs.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker sends a specially crafted GET request to the \u003ccode\u003e/download/resources/\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe path includes a double URL-encoded traversal sequence (e.g., \u003ccode\u003e..%3a%3a\u003c/code\u003e) designed to survive initial Tomcat normalization.\u003c/li\u003e\n\u003cli\u003eThe webresource router performs a secondary URL-decode on the URI.\u003c/li\u003e\n\u003cli\u003eThe router's \u003ccode\u003eunescapeSlashes\u003c/code\u003e function converts the \u003ccode\u003e::\u003c/code\u003e sequence into a \u003ccode\u003e/\u003c/code\u003e path separator.\u003c/li\u003e\n\u003cli\u003eThe application constructs a final path, resulting in a traversal sequence like \u003ccode\u003e../../WEB-INF/web.xml\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eServletContext.getResourceAsStream\u003c/code\u003e function resolves the path relative to the application root without further security gating.\u003c/li\u003e\n\u003cli\u003eThe application returns the contents of the requested sensitive configuration file in the HTTP response body.\u003c/li\u003e\n\u003cli\u003eAttacker harvests credentials or application metadata from the returned file for subsequent lateral movement.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated information disclosure of highly sensitive configuration data. Successful exploitation provides attackers with the necessary building blocks - such as database credentials and API keys - to compromise the underlying server infrastructure, escalate privileges, or facilitate lateral movement within the network. Multiple self-hosted product lines are affected, and active exploitation has been confirmed following the release of public exploit tooling.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and mitigation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all affected Atlassian Data Center and Server products to the fixed versions specified in the Atlassian September 2026 security advisory immediately.\u003c/li\u003e\n\u003cli\u003eImplement a WAF or reverse-proxy rule to block all incoming requests containing \u003ccode\u003e%3a%3a\u003c/code\u003e or \u003ccode\u003e::\u003c/code\u003e character sequences in the URL path.\u003c/li\u003e\n\u003cli\u003eDeploy the specific Tomcat RewriteValve or \u003ccode\u003eurlrewrite.xml\u003c/code\u003e mitigation rules provided by Atlassian for instances where immediate patching is not feasible.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous GET requests targeting the \u003ccode\u003e/download/resources/\u003c/code\u003e endpoint with traversal patterns containing \u003ccode\u003e..%3a%3a\u003c/code\u003e or \u003ccode\u003e..::\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T10:33:48Z","date_published":"2026-10-06T20:29:05Z","id":"https://feed.craftedsignal.io/briefs/2026-10-atlassian-path-traversal/","summary":"An unauthenticated arbitrary file read vulnerability (CVE-2026-21589) in multiple Atlassian Data Center products allows attackers to access sensitive configuration files via a path traversal flaw in the webresource router.","title":"Critical Path Traversal in Atlassian Data Center Products (CVE-2026-21589)","url":"https://feed.craftedsignal.io/briefs/2026-10-atlassian-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Confluence Data Center (\u003c 9.2.26, 10.2.19)","version":"https://jsonfeed.org/version/1.1"}