Security News

Critical Atlassian Data Center Flaw Under Active Attack, Exposing Files and Credentials

Infosecurity Magazine · 8 Oct 2026
Key Takeaway If you run self-managed Atlassian Data Center products, check Atlassian's October 5 advisory for CVE-2026-21589 now, apply the recommended fixes, and review your systems for signs of unauthorised access.

A critical vulnerability in Atlassian Data Center products is reportedly being exploited in the wild. Tracked as CVE-2026-21589, the flaw was described by Atlassian in an October 5 advisory as an arbitrary file access issue with a severity score (CVSS) of 9.3. It affects eight Atlassian products widely used in enterprise IT systems. Data Center products are the self-managed versions, where the customer runs the software and looks after the underlying infrastructure, either in its own data center or on a public cloud such as AWS or Azure.

An attacker with no login access can exploit the flaw to read specific files in each product's web application root directory. In an analysis published on October 6, WatchTowr found that the affected products share a common Atlassian Web Resource library, which contains the vulnerable path-handling logic. This allows an attacker to bypass path-traversal protections. That shared component explains why seemingly different products are affected.

The risk may go beyond reading files. WatchTowr noted that Atlassian Crowd, which can act as a central identity and authentication service for other Atlassian products, plays an important role in a potential attack chain. When Jira is configured to use Crowd, a Jira configuration file holds the credentials it uses to talk to Crowd. WatchTowr demonstrated that the flaw can expose these credentials. An attacker could then use them to interact with Crowd, potentially creating or modifying users and privileges. In the demonstration, this offered a path towards Jira administrator-level access.

Atlassian CVE-2026-21589 Vulnerability Active Exploitation Jira

Summarised by CISO AI from Infosecurity Magazine, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.