CVE-2026-21589 is a path traversal vulnerability affecting Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Vulnerable path handling in the shared atlassian-plugins-webresource component converts double-colon sequences into forward slashes during resource resolution, allowing crafted requests to bypass traversal protections and retrieve protected files within the application's web root. Exploitation requires no authentication or user interaction, but the attacker must know the exact target filename and path. The vulnerability does not provide directory enumeration or unrestricted operating-system file access.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
The supplied repository contains README.md (2,493 bytes) and a standalone Python exploit/scanner, poc.py (6,223 bytes). The README describes the claimed CVE-2026-21589, affected resource components, invocation options, and response indicators. The code uses requests and colorama, accepts a single target or a target-list file, and runs concurrent per-target checks with 20 workers by default. Each worker submits hardcoded double-colon traversal requests for Jira, Confluence, and Bitbucket configuration files. A matching Confluence response triggers an additional request for Crowd credentials, making this more than a detection-only script. Targets are operator-supplied; no fixed callback or exfiltration server is present, and the author website is not contacted. TLS certificate verification is disabled, the normal request timeout defaults to 15 seconds, and the credential request has no explicit timeout. Exceptions are silently suppressed. Credential parsing only splits on whitespace and may fail on conventional key=value properties. Explicitly schemed target URLs bypass the separate port argument. The tool prints findings and extracted credential fields but does not save full response bodies or expose arbitrary file selection. The claimed CVE association, affected versions, and exploit effectiveness are not independently verified by the supplied material. Repository URL, Git reference, and archive size were not provided; empty metadata and a zero size represent unavailable information, not a measured archive.
The repository contains five files: a standalone Python entry point (poc.py), a detailed README, a requests dependency declaration, an MIT license, and a .gitignore covering generated results, target lists, XML output, and PEM files. The declared file sizes total 31,472 bytes; the repository URL, Git reference, and archive size were not supplied, so URL/ref are empty and size_bytes is an unknown-value placeholder of 0. The code implements an unauthenticated web-resource traversal exploit attributed by the repository to CVE-2026-21589. Its stated mechanism is late conversion of '::' into '/', allowing '..::' traversal sequences to reach known files inside the Tomcat application root. Visible product profiles cover Jira, Confluence, and Bitbucket, with content markers com.atlassian.jira.web.ServletContextProviderListener, com.atlassian.confluence.impl.webapp.ServletsInitializer, and com.atlassian.plugin.servlet.ResourceDownloadUtils respectively. Other Atlassian products are claimed affected in the documentation but have no supplied route profiles. Exact affected versions are unspecified; the README lists patch releases rather than complete vulnerable version ranges. The documented capabilities include vulnerability checking, selected-file retrieval, optional Crowd credential parsing, plain or encoded-colon requests, TLS-verification bypass, and threaded batch reporting. The visible main-function tail confirms exploit result handling, optional file saving through a second read request, credential display, and success-dependent single-target exit codes. Crowd credentials are only read and displayed; there is no demonstrated Crowd API action, shell payload, or write primitive. Target addresses are supplied by the operator rather than hardcoded. Branding URLs are metadata, not demonstrated command-and-control or exfiltration destinations. A substantial middle section of poc.py is explicitly truncated. Consequently, request construction, response validation, CLI defaults, and batch behavior cannot be fully audited from the supplied content. This is an exploit rather than detection-only code, and no evidence of a fake exploit is visible, but runtime functionality and the external CVE/product claims have not been independently verified.
The supplied repository contains README.md and one standalone Python exploit, poc.py, using requests and standard-library concurrency. It is not a framework module. The README claims CVE-2026-21589 arises when Router.unescapeSlashes() translates double colons into slashes after Tomcat URI normalization, allowing unauthenticated traversal into web-application resources. The code implements repeated '..::' traversal segments, checks HTTP 200 responses longer than 20 characters, and confirms a product-specific marker in WEB-INF/web.xml before attempting to read Crowd credentials. Its file-access primitive targets the deployed webroot, not demonstrated unrestricted operating-system filesystem access. The script supports individual targets and concurrent batch processing of a JSON mapping containing lists of IP/port records. It deduplicates hosts and accepts ports 80, 443, 8080, 8443, 8090, 8095, 8888, and 9999; only 443 and 8443 are treated as HTTPS. Twenty workers and six-second timeouts are defaults. TLS certificate validation is disabled, warnings are suppressed, and traversal requests do not follow redirects. There are no hardcoded external collection servers or target IP addresses; target URLs are operator-supplied, while the Crowd URL is extracted from the target's configuration. With --crowd-pwn, stolen application credentials are used for HTTP Basic authentication, account creation, and membership in jira-administrators. This is a conditional privilege-escalation chain, not guaranteed administrator takeover: it depends on Crowd application permissions, URL correctness, and Jira's group mapping. Batch output can contain plaintext stolen credentials and generated account passwords. Important limitations: --file and --list are parsed but never used, so the documented arbitrary-file CLI command does not select a different file. The README discusses encoded '..%3a%3a' bypasses, but the implementation sends literal '..::'. Crowd URL normalization can duplicate the /crowd context or concatenate paths incorrectly for some configuration values. Property parsing assumes whitespace-separated values and can mishandle common key=value formatting. Broad exception suppression and fixed anchors can produce false negatives, and API exceptions are not caught. No runtime validation or independent confirmation of the CVE and version claims is available from the supplied content; no clear malicious decoy behavior is evident. The README lists fixed releases as Jira Software/JSM 9.12.40, 10.3.26, and 11.3.12; Confluence 9.2.26 and 10.2.19; Bitbucket 9.4.26, 10.2.8, and 10.5.1; Bamboo 10.2.24 and 12.1.12; Crowd 6.3.7, 7.0.3, 7.1.7, and 7.2.4; and Crucible/Fisheye 4.9.15. Those applicability claims have not been independently verified. The original repository URL, analyzed git reference, archive path, and archive size were not supplied; empty strings and zero represent unavailable repository metadata, not an empty archive.
The supplied repository contains three files: a Nuclei template, a standalone Python tool, and a partially supplied README. The main framework artifact, CVE-2026-21589.yaml, issues up to three product-specific traversal requests against Jira, Confluence, and Bitbucket, stopping at the first match. It requires HTTP 200 together with a recognizable XML marker, so detection actively attempts file disclosure rather than merely checking a version. Its payloads are hardcoded configuration-file reads, not shells or code-execution payloads. The companion Python script uses only the standard library. It supports selecting a resource-router prefix, sweeping traversal depths 2 through 8, trying five route variants, choosing a target file, and saving the returned bytes locally. It disables HTTPS certificate verification and sends the distinctive User-Agent 'CVE-2026-21589-check'. Unlike the template, it treats any nonempty HTTP 200 response as success, which can produce false positives. Its interpretation of HTTP 404 as likely patched is also not definitive. It uses the supplied URL's host and port but ignores its path, limiting deployment-context support. The claimed mechanism is inconsistent path normalization in Atlassian's shared webresource library: encoded or literal double-colon traversal components become separators during resource resolution, exposing files inside the application webroot. There is no directory enumeration, demonstrated access outside that webroot, file modification, credential-reuse workflow, or command execution. Documentation describes possible credential disclosure from crowd.properties, but neither default probe requests that file. No fixed remote target, callback, or exfiltration destination appears in the executable artifacts; target hosts are supplied at runtime. Reference URLs and README images are documentation links, not exploit network calls. The README claims additional affected products and patch versions; those claims and the template's verified flag were not independently validated. There is no obvious malicious local behavior or evidence that the code is a fake exploit. The template and README use different CVSS versions and CWE classifications. No original repository URL, git reference, or archive size was supplied; empty repository metadata and a zero size indicate unavailable information.
The supplied repository contains a 10,193-byte README and a 16,327-byte standalone Python script. Both file contents are truncated, so this is a static assessment of the visible excerpts rather than a complete implementation review. No repository URL, git reference, or archive size was supplied; empty metadata and size 0 represent unavailable information, not an empty repository. The script implements a plausible file-disclosure-to-account-takeover chain attributed to CVE-2026-21589. It constructs resource paths containing '..::' traversal components, relying on the claimed server-side conversion of '::' to '/'. Product-specific probes check web.xml or urlrewrite.xml for identifying class names before attempting disclosure of Crowd connector configuration. Visible routing profiles support Jira, Confluence, and Bitbucket; the README's additional product claims are not backed by corresponding profiles in the supplied code. The described read primitive is limited to the webapp context, not demonstrated as unrestricted operating-system file access. The documented second phase extracts plaintext Crowd application credentials. The visible final phase attempts user creation, handles an existing-user response, and adds the selected account to a product administrator group or crowd-administrators. A username, password, email, and optional group are argument-driven. The code reports success based on a successful membership API response; it does not visibly verify a subsequent administrator login. Successful takeover depends on Crowd reachability, writable application permissions, directory capabilities, and correct group mapping. No SSRF pivot or shell payload is visible. HTTP helpers disable TLS certificate verification, and warnings are suppressed. File-read GET requests do not follow redirects by default, whereas JSON POST requests do. A warning statement in read_file is unreachable because it follows a return. The imported systext module is not included among the two repository files, and no dependency manifest is supplied. Important functions, argument parsing, credential parsing, and precise Crowd REST routes are hidden by truncation. The code is exploit-oriented rather than detection-only, and no obvious malicious decoy behavior is visible, but neither exploit success nor the CVE and fixed-version claims can be independently verified from this material.
The supplied repository contains six files: two standalone Python entry points, README.md, an MIT LICENSE, requirements.txt declaring PySocks, and .gitignore. exploit.py is an intended unauthenticated application-file disclosure toolkit; safecheck.py is a separate detection-only exposure scanner. Both contain main guards, threaded multi-target orchestration, logging, and JSON/CSV report dispatch. The README additionally advertises CIDR expansion, proxy/Tor support, retries, connection pooling, rate limiting, and exploit-specific stealth, User-Agent rotation, custom file selection, and depth sweeping; their implementations are omitted from the supplied excerpts. The claimed exploit mechanism uses encoded '..::' traversal through product-specific webresource anchors, followed by application decoding and slash unescaping, to reach ServletContext resources such as WEB-INF configuration files. The visible exploit configuration defines seven product profiles, fifteen candidate files, and seven credential-pattern categories. Jira Service Management is claimed as an eighth affected product but has no separate exploit profile; safecheck.py does include a separate jira_sm profile. Product markers include Java class/package strings, while the scanner also lists Atlassian-related response headers for fingerprinting. File access is described as constrained to known paths inside the application root, not unrestricted operating-system file access. Important limitations: both Python files are substantially truncated, including request construction, response validation, version comparison, and credential extraction execution. Consequently, working exploitation and the claimed CVE/advisory/version ranges cannot be independently confirmed from this material. No visible evidence establishes malicious operator-side commands, a callback endpoint, or exfiltration to a third party, but omitted code prevents a complete safety assessment. The README repeatedly names safechecker.py, whereas the actual supplied entry point is safecheck.py; it also references an absent vuln.png. Repository URL is inferred from the README clone command. No git reference or archive size was supplied; the six listed file sizes total 70,980 bytes, while size_bytes is 0 as an unknown-value placeholder.
The supplied repository contains a 2,556-byte README and a 3,887-byte standalone Python script, totaling 6,443 bytes of listed file content. No repository URL, Git reference, or archive size was supplied; the archive-size field is therefore set to 0 as an unknown placeholder. The README describes the claimed vulnerability, affected products, fixes, usage, and advisory references. The executable script uses only Python standard-library modules and is not associated with an exploit framework. The script implements an active file-disclosure attempt rather than detection alone. It constructs /download/ resource requests using a hardcoded Jira anchor and repeated '..%3a%3a' sequences. According to the repository, application-level URI decoding and '::' slash unescaping produce traversal after Tomcat normalization, allowing ServletContext.getResourceAsStream to access files within the web application root. The README attributes remediation to containment checks in ResourceFactory and identifies webresource 7.2.17 and 8.0.14 as fixed versions. These CVE, advisory, affected-product, and patch claims have not been independently verified from the supplied content. Capabilities include choosing the requested file, testing five route prefixes, sweeping traversal depths 2–8, configuring a timeout, previewing retrieved content, and optionally writing the response locally. HTTPS certificate verification is disabled. Requests carry the distinctive User-Agent 'CVE-2026-21589-check'; there is no fixed callback or exfiltration destination. The script does not follow redirects, ignores any context path in the supplied base URL, and terminates on a network error rather than continuing the sweep. Its HTTP-status verdicts are heuristic: a 404 does not prove patching, and a nonempty 200 response does not prove successful file disclosure. No destructive commands or concealed secondary payloads are apparent, but successful exploitation and applicability beyond the hardcoded Jira anchor remain unverified.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
314 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unauthenticated arbitrary file-read vulnerability affecting multiple Atlassian products, rated CVSS 4.0 9.3. Crafted HTTP requests exploit resource-path processing to retrieve known files within the application web root, without user interaction. The flaw does not provide directory enumeration or direct remote code execution. Researchers demonstrated that exposed Jira–Crowd integration credentials could enable user creation and Jira administrative access in permissively configured deployments. Fixed releases became available on October 5, 2026. The report describes detection activity but does not establish successful exploitation in the wild; Atlassian reported no evidence of exploitation affecting Cloud customers at disclosure.
A critical vulnerability rated CVSS 9.3 in a shared library used by Atlassian self-hosted Data Center products. It allows unauthenticated remote attackers to read specific files in the web application's root directory, provided they know the exact filename and path; it does not permit directory listing. In Jira deployments integrated with Crowd, researchers demonstrated reading plaintext Crowd application credentials from a configuration file, then using those credentials to create a user and grant Jira administrator privileges. The article reports real-world exploitation attempts against honeypots, not confirmed compromises of production organizations.
A critical arbitrary-file-access vulnerability affecting multiple Atlassian products, rated CVSS 9.3. Unauthenticated remote attackers can read files within the web application's root directory if they know the exact filenames and paths, but cannot enumerate filenames or list directories. Exposed files such as WEB-INF/web.xml and WEB-INF/classes/crowd.properties may contain sensitive configuration information and plaintext management-account credentials. The report states that exploitation attempts were detected in Previdian's honeypot network within two hours of public proof-of-concept release. Atlassian has released patched versions and provides temporary mitigation and log-review guidance.
A critical unauthenticated arbitrary file-read vulnerability, rated CVSS 9.3, affecting eight Atlassian products through vulnerable path-handling logic in the shared atlassian-plugins-webresource library. Attackers can bypass path-traversal protections to read specific files within application webroots. WatchTowr demonstrated retrieval of Crowd integration credentials from Jira's crowd.properties file, potentially enabling user and privilege manipulation through Crowd and a path to Jira administrator access. Exploitation targeting Bamboo Data Center has been reported.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.