
PEACH
Un cadre d’isolation des locataires
CVE-2026-21589 is a critical Arbitrary File Access (path traversal) vulnerability affecting eight Atlassian Data Center and Server products: Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye. An unauthenticated remote attacker can access specific files within the web application root directory without any credentials, provided they know the exact file name and path. The vulnerability was published on October 5–6, 2026, with patches released simultaneously. It carries a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory, Feedly).
The vulnerability is a path traversal / arbitrary file read flaw (related to improper limitation of a pathname to a restricted directory) that allows unauthenticated network access to files within the web application root. No CWE has been formally assigned in the advisory, but the behavior is consistent with CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). Exploitation requires no privileges, no user interaction, and no special attack conditions — only prior knowledge of the target file's exact name and path; directory listing or enumeration is not possible through this vulnerability. The flaw was introduced across a wide range of product versions: Bitbucket Data Center >= 4.6.0, Confluence Data Center >= 5.10.0, Crowd Data Center >= 2.11.0, Jira Software Data Center >= 7.1.0, Jira Service Management Data Center >= 3.1.0, and Bamboo Data Center >= 7.0.1 (GitHub Advisory). A technical write-up and proof-of-concept analysis has been published by watchTowr (watchTowr).
Successful exploitation allows an unauthenticated attacker to read arbitrary files within the web application root directory of affected Atlassian products, potentially exposing sensitive configuration files, credentials, API tokens, or other data stored in those locations. The CVSS v4.0 scoring reflects high confidentiality impact on both the vulnerable system and subsequent systems, with high integrity and availability impact on subsequent systems — indicating that exposed credentials or configuration data could enable further compromise, lateral movement, or privilege escalation across the broader environment. All self-hosted (Server and Data Center) deployments of the affected products across a wide version range are at risk; cloud-hosted instances are not affected (GitHub Advisory, Feedly).
Exploitation has been reported in the wild, with watchTowr publishing both a technical FAQ and a proof-of-concept/analysis for this vulnerability (watchTowr). The vulnerability requires no authentication, no user interaction, and no special preconditions beyond network access and knowledge of a target file path, making it highly automatable. Nessus detection plugins (IDs 363023, 363014, 363027) have been released, indicating active scanner coverage. No specific threat actor attribution or CISA KEV catalog listing was identified in available sources at time of reporting, and no EPSS score was available in the provided data (Feedly).
../, %2e%2e%2f, or encoded variants) or direct references to known configuration file paths; repeated requests from a single external IP to application root-relative file paths.web.xml, *.properties, or other configuration files in the application root; anomalous access patterns from IPs with no prior authenticated sessions.Atlassian has released patched versions for all affected products. Organizations should upgrade to the following fixed versions as soon as possible:
All Server editions (Bitbucket Server, Confluence Server, Crowd Server, Bamboo Server, Jira Software Server, Jira Service Management Server) are affected across all versions and should be migrated to Data Center or upgraded immediately. As interim mitigations, restrict network access to affected systems, deploy WAF rules to block path traversal patterns, and review access logs for suspicious unauthenticated file access (GitHub Advisory, Feedly).
The vulnerability received significant media and community attention upon disclosure. The Hacker News, The Register, Help Net Security, GBHackers, and CyberSecurityNews all published coverage highlighting the critical severity and broad product scope (The Hacker News, The Register, Help Net Security). watchTowr published both a detailed FAQ and a technical analysis/PoC, generating notable discussion on Mastodon/Infosec.exchange and Reddit's r/SecOpsDaily. The security community broadly emphasized the urgency of patching given the unauthenticated nature of the exploit and the wide deployment footprint of affected Atlassian products.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."