Image: storage.ghost.io · rights & removal
Executive Summary
Facts Only
* CVE-2026-21589 was reported by Atlassian as "Arbitrary File Access" or "Arbitrary File Read."
* The vulnerability affects versions of Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye.
* Affected fixed versions include specific versions for each product listed in the advisory.
* Investigation focused on the file `atlassian-plugins-webresource*.jar`.
* Code analysis of `Router.java` revealed functions that replace double colons (`::`) with forward slashes (`/`).
* A potential path traversal payload similar to `..::..::..::..::::file.txt` was developed based on observed function calls and path construction.
* Exploitation routes were demonstrated, including accessing files in the application's webroot like `WEB-INF/web.xml`.
* Specific exploitation paths were shown for Jira (e.g., `/download/resources/.../..::..::..::..::..::WEB-INF::web.xml`) and Confluence.
* The Atlassian Crowd configuration file, located at `WEB-INF/classes/crowd.properties`, was found to contain plaintext application passwords and URLs.
* Accessing the Atlassian Crowd endpoint with these leaked credentials allows for user management actions, including user creation and group administration in Jira.
Full Take
From the original · WatchTowr Labs
Welcome back to yet another episode of "security was taken seriously". Being who we are (and constantly being exposed to what we see…), we recognize we have been doomed to eternal damnation as we keep on watching security best practices crumble behind “secure by design” public statements.Read the full story at labs.watchtowr.com
Sentinel — Human
This content appears to be a detailed breakdown of a security vulnerability exploitation chain, written by an expert researcher, focusing on technical execution rather than broad commentary.
