Atlassian Products Vulnerable to Arbitrary File Access via Directory Traversal
Atlassian products are affected by CVE-2026-21589, an arbitrary file access vulnerability that allows attackers to read sensitive files by exploiting a unique directory traversal mechanism.

Atlassian has released patches for several of its products to address CVE-2026-21589, a critical "Arbitrary File Access" vulnerability. This flaw enables attackers to read arbitrary files within the web application's directory, potentially exposing sensitive configuration files and other critical data.
The vulnerability leverages a directory traversal technique that differs from typical exploits. Atlassian products employ a "::" pattern to replace forward slashes, a mechanism intended to prevent such attacks. However, attackers can exploit this by manipulating the "::" pattern, which the server may interpret as a slash, thereby bypassing the intended security controls and navigating the file system.
Researchers at Watchtowr have detailed the vulnerability, providing proof-of-concept URLs that demonstrate how an attacker can access files like WEB-INF/web.xml or WEB-INF/urlrewrite.xml. These configuration files are essential for web applications and can contain sensitive information, similar to how /etc/passwd might be targeted in other systems. The success of the exploit is contingent on the existence of the targeted file within the web application's directory.
Exploitation attempts targeting this vulnerability have already been observed in the wild. The SANS Internet Storm Center reported seeing scans hitting their honeypots, originating from IP addresses associated with Digital Ocean. The timing and nature of these scans suggest they are part of a coordinated effort by a single threat actor.
The specific files targeted in the observed exploit attempts include jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml, com.atlassian.bitbucket.server.bitbucket-webpack-INTERNAL:avatar/avatar/..::..::..::..::..::WEB-INF::urlrewrite.xml, and com.atlassian.confluence.plugins.dashboard-actions/images/..::..::..::..::..::..::..::..::WEB-INF::web.xml. These examples highlight the attacker's focus on accessing critical configuration files within the WEB-INF directory.
While the vulnerability allows access to files within the web application's directory, it does not permit access to system-level files like /etc/passwd unless they happen to be located within that specific web application context. The unique "::" pattern replacement is the key mechanism that differentiates this exploit from more common directory traversal methods.
Atlassian has released patches for the affected products, and users are strongly advised to apply these updates as soon as possible to mitigate the risk of exploitation. The ongoing in-the-wild exploitation underscores the urgency of patching this vulnerability to protect sensitive data and maintain the integrity of Atlassian application deployments.