CVE-2026-21589 is a path traversal vulnerability affecting Atlassian Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. An unauthenticated remote attacker can read specific files within an affected application's web root directory by knowing the target file's exact name and path. The vulnerability does not permit directory enumeration or establish unrestricted access to files elsewhere on the server. Sensitive files stored within the accessible directory can increase the confidentiality impact. Older Server editions and unsupported deployments may also be affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
The supplied repository contains three files: a Nuclei template, a standalone Python tool, and a partially supplied README. The main framework artifact, CVE-2026-21589.yaml, issues up to three product-specific traversal requests against Jira, Confluence, and Bitbucket, stopping at the first match. It requires HTTP 200 together with a recognizable XML marker, so detection actively attempts file disclosure rather than merely checking a version. Its payloads are hardcoded configuration-file reads, not shells or code-execution payloads. The companion Python script uses only the standard library. It supports selecting a resource-router prefix, sweeping traversal depths 2 through 8, trying five route variants, choosing a target file, and saving the returned bytes locally. It disables HTTPS certificate verification and sends the distinctive User-Agent 'CVE-2026-21589-check'. Unlike the template, it treats any nonempty HTTP 200 response as success, which can produce false positives. Its interpretation of HTTP 404 as likely patched is also not definitive. It uses the supplied URL's host and port but ignores its path, limiting deployment-context support. The claimed mechanism is inconsistent path normalization in Atlassian's shared webresource library: encoded or literal double-colon traversal components become separators during resource resolution, exposing files inside the application webroot. There is no directory enumeration, demonstrated access outside that webroot, file modification, credential-reuse workflow, or command execution. Documentation describes possible credential disclosure from crowd.properties, but neither default probe requests that file. No fixed remote target, callback, or exfiltration destination appears in the executable artifacts; target hosts are supplied at runtime. Reference URLs and README images are documentation links, not exploit network calls. The README claims additional affected products and patch versions; those claims and the template's verified flag were not independently validated. There is no obvious malicious local behavior or evidence that the code is a fake exploit. The template and README use different CVSS versions and CWE classifications. No original repository URL, git reference, or archive size was supplied; empty repository metadata and a zero size indicate unavailable information.
The supplied repository contains a 10,193-byte README and a 16,327-byte standalone Python script. Both file contents are truncated, so this is a static assessment of the visible excerpts rather than a complete implementation review. No repository URL, git reference, or archive size was supplied; empty metadata and size 0 represent unavailable information, not an empty repository. The script implements a plausible file-disclosure-to-account-takeover chain attributed to CVE-2026-21589. It constructs resource paths containing '..::' traversal components, relying on the claimed server-side conversion of '::' to '/'. Product-specific probes check web.xml or urlrewrite.xml for identifying class names before attempting disclosure of Crowd connector configuration. Visible routing profiles support Jira, Confluence, and Bitbucket; the README's additional product claims are not backed by corresponding profiles in the supplied code. The described read primitive is limited to the webapp context, not demonstrated as unrestricted operating-system file access. The documented second phase extracts plaintext Crowd application credentials. The visible final phase attempts user creation, handles an existing-user response, and adds the selected account to a product administrator group or crowd-administrators. A username, password, email, and optional group are argument-driven. The code reports success based on a successful membership API response; it does not visibly verify a subsequent administrator login. Successful takeover depends on Crowd reachability, writable application permissions, directory capabilities, and correct group mapping. No SSRF pivot or shell payload is visible. HTTP helpers disable TLS certificate verification, and warnings are suppressed. File-read GET requests do not follow redirects by default, whereas JSON POST requests do. A warning statement in read_file is unreachable because it follows a return. The imported systext module is not included among the two repository files, and no dependency manifest is supplied. Important functions, argument parsing, credential parsing, and precise Crowd REST routes are hidden by truncation. The code is exploit-oriented rather than detection-only, and no obvious malicious decoy behavior is visible, but neither exploit success nor the CVE and fixed-version claims can be independently verified from this material.
The supplied repository contains six files: two standalone Python entry points, README.md, an MIT LICENSE, requirements.txt declaring PySocks, and .gitignore. exploit.py is an intended unauthenticated application-file disclosure toolkit; safecheck.py is a separate detection-only exposure scanner. Both contain main guards, threaded multi-target orchestration, logging, and JSON/CSV report dispatch. The README additionally advertises CIDR expansion, proxy/Tor support, retries, connection pooling, rate limiting, and exploit-specific stealth, User-Agent rotation, custom file selection, and depth sweeping; their implementations are omitted from the supplied excerpts. The claimed exploit mechanism uses encoded '..::' traversal through product-specific webresource anchors, followed by application decoding and slash unescaping, to reach ServletContext resources such as WEB-INF configuration files. The visible exploit configuration defines seven product profiles, fifteen candidate files, and seven credential-pattern categories. Jira Service Management is claimed as an eighth affected product but has no separate exploit profile; safecheck.py does include a separate jira_sm profile. Product markers include Java class/package strings, while the scanner also lists Atlassian-related response headers for fingerprinting. File access is described as constrained to known paths inside the application root, not unrestricted operating-system file access. Important limitations: both Python files are substantially truncated, including request construction, response validation, version comparison, and credential extraction execution. Consequently, working exploitation and the claimed CVE/advisory/version ranges cannot be independently confirmed from this material. No visible evidence establishes malicious operator-side commands, a callback endpoint, or exfiltration to a third party, but omitted code prevents a complete safety assessment. The README repeatedly names safechecker.py, whereas the actual supplied entry point is safecheck.py; it also references an absent vuln.png. Repository URL is inferred from the README clone command. No git reference or archive size was supplied; the six listed file sizes total 70,980 bytes, while size_bytes is 0 as an unknown-value placeholder.
The supplied repository contains a 2,556-byte README and a 3,887-byte standalone Python script, totaling 6,443 bytes of listed file content. No repository URL, Git reference, or archive size was supplied; the archive-size field is therefore set to 0 as an unknown placeholder. The README describes the claimed vulnerability, affected products, fixes, usage, and advisory references. The executable script uses only Python standard-library modules and is not associated with an exploit framework. The script implements an active file-disclosure attempt rather than detection alone. It constructs /download/ resource requests using a hardcoded Jira anchor and repeated '..%3a%3a' sequences. According to the repository, application-level URI decoding and '::' slash unescaping produce traversal after Tomcat normalization, allowing ServletContext.getResourceAsStream to access files within the web application root. The README attributes remediation to containment checks in ResourceFactory and identifies webresource 7.2.17 and 8.0.14 as fixed versions. These CVE, advisory, affected-product, and patch claims have not been independently verified from the supplied content. Capabilities include choosing the requested file, testing five route prefixes, sweeping traversal depths 2–8, configuring a timeout, previewing retrieved content, and optionally writing the response locally. HTTPS certificate verification is disabled. Requests carry the distinctive User-Agent 'CVE-2026-21589-check'; there is no fixed callback or exfiltration destination. The script does not follow redirects, ignores any context path in the supplied base URL, and terminates on a network error rather than continuing the sweep. Its HTTP-status verdicts are heuristic: a 404 does not prove patching, and a nonempty 200 response does not prove successful file disclosure. No destructive commands or concealed secondary payloads are apparent, but successful exploitation and applicability beyond the hardcoded Jira anchor remain unverified.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
223 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical path traversal vulnerability affecting multiple Atlassian Data Center products allows unauthenticated remote attackers to read files within the web application root directory. Attackers must know exact filenames because directory enumeration is not possible. Exposed files could include configurations containing plain-text credentials. Atlassian released an advisory on October 5, 2026, with patches immediately available, and urged self-hosted users to upgrade. Cloud users are not affected because fixes have already been applied. The reported maximum CVSS v4.0 score is 9.3.
A critical arbitrary file access vulnerability affecting multiple self-hosted Atlassian Data Center products. An unauthenticated attacker who knows an exact file name and path can access files within the application's web root. Updated versions are available, and administrators are urged to patch immediately. The content states that cloud customers are unaffected due to automatic patching and that Atlassian has found no current evidence of exploitation.
An arbitrary file access vulnerability affecting multiple Atlassian products allows attackers to read files within a web application's directory, potentially exposing sensitive configuration information. The referenced article title indicates scanning for the vulnerability. Atlassian published patches on October 5.
A directory traversal vulnerability affecting Atlassian web applications allows attackers to read existing files within the application's directory, potentially exposing sensitive configuration information. Exploit paths use '::' sequences that the server translates into '/', enabling traversal. The report documents active scanning and exploitation attempts against honeypots, but does not establish successful compromise. Access does not extend outside the web application's directory.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.