Tech News
← Home  ·  All topics

Confluence

2 GoKawiil briefs on this topic

Active exploitation hits Atlassian flaw CVE-2026-21589 after PoC release

Security firm Previdian detected exploitation attempts against CVE-2026-21589, an unauthenticated arbitrary file-access vulnerability affecting eight self-hosted Atlassian products including Jira, Confluence, and Bitbucket, shortly after watchTowr published a technical report explaining the bug. The flaw stems from a shared web-resource library that mishandles double-colon characters, letting attackers craft directory-traversal requests through plugin endpoints to read protected files without logging in. Atlassian had already issued an advisory urging administrators to patch self-hosted instances, saying it cannot confirm which customer deployments may already be compromised.

Atlassian patches critical arbitrary file-access bug across Jira, Confluence, Bitbucket

Atlassian disclosed CVE-2026-21589, a critical vulnerability letting unauthenticated attackers read specific files inside the web root of several self-hosted Data Center products, including Confluence, Jira, Bitbucket, Bamboo, Crowd, Crucible and Fisheye. Exploitation requires knowing the exact file name and path, and the flaw does not allow directory listing. Atlassian has released patched versions for each affected product and says Cloud customers are already protected.