A critical vulnerability identified as CVE-2026-21589 is actively being exploited in Atlassian Data Center products, posing significant risks to enterprise IT systems. Described as an arbitrary file access flaw, this vulnerability carries a high severity score of 9.3 on the CVSS scale. It affects eight self-managed versions of Atlassian products. These products are typically hosted in a company's data center or on controlled public cloud infrastructure such as AWS or Azure. Attackers can exploit this flaw without login credentials to access specific files within the product's web application root directory.

According to an analysis by WatchTowr, the vulnerability is found in the Atlassian-plugins-webresource library, a common component across the affected products. This library contains flawed path-handling logic, allowing attackers to bypass protections and read files from the application's root. This shared component explains why multiple products are impacted. Additionally, Atlassian Crowd, an identity and authentication service, plays a critical role in the potential attack chain. When integrated, it can allow attackers to extract credentials and potentially modify user privileges, leading to increased access.

WatchTowr demonstrated how this vulnerability could be exploited to gain administrator-level access to Jira, illustrating the threat's seriousness. VulnCheck has also reported active exploitation targeting Bamboo Data Center, although the US Cybersecurity and Infrastructure Security Agency (CISA) has not yet included it in their catalog of known exploited vulnerabilities. Atlassian has issued an advisory urging customers to update to patched versions or apply temporary mitigations if immediate patching is not feasible. Customers are encouraged to work with their security teams to assess their systems for signs of compromise. WatchTowr has made available a detection artifact generator to aid in identifying vulnerabilities within Jira, Confluence, and Bitbucket instances.