POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Web appcritical

CVE-2026-21589 — Atlassian Data Center Pre-Auth Arbitrary File Read (:: Traversal)

October 8, 2026 · 75 views

Atlassian DC/self-managed (Jira, Confluence, Bitbucket, etc.): atlassian-plugins-webresource unescapeSlashes converts :: to / — ..:: traversal on /download/resources/ reads files under web app root (WEB-INF/web.xml, crowd.properties). CVSS 4.0 9.3 Critical, unauthenticated, read-only not RCE. Python PoC: check/exploit, --grab-crowd, mass -j. Marker POCBIT-21589-OK.

#atlassian#jira#confluence#bitbucket#lfi#path-traversal#unauthenticated#critical#file-read

CVE:

CVE-2026-21589

Date:

2026-10-08

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-21589 — Atlassian Data Center / self-managed products — unauthenticated arbitrary file read inside the Tomcat web application root via atlassian-plugins-webresource (:: → / in Router.unescapeSlashes()).

| | | |---|---| | Products | Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, Fisheye (DC / on-prem) | | Type | Read-only (not write/RCE by itself) | | Auth | None | | CVSS 4.0 | 9.3 Critical | | Verify marker | POCBIT-21589-OK | | Cloud | Patched; PoC targets self-hosted |

Limits: no directory listing; paths must be known; reads stay inside web app root. Optional chain: WEB-INF/classes/crowd.properties → Crowd app credentials (separate impact).

PoC page: https://pocbit.org/pocs/cve-2026-21589

GitHub: murrez/CVE-2026-21589

CVE.org: CVE-2026-21589

Example patched versions

| Product | Patched at or above (examples) | |---------|--------------------------------| | Jira DC | 9.12.40, 10.3.26, 11.3.12 | | Confluence DC | 9.2.26, 10.2.19 | | Bitbucket DC | 9.4.26, 10.2.8, 10.5.1 |

See vendor advisory for full matrix.

Bundled tool (Python 3.10+)

Download cve-2026-21589.py — writes poc.py, requirements.txt.

python cve-2026-21589.py
pip install requests

python poc.py -u https://jira.example.com --mode check
python poc.py -u https://jira.example.com --mode exploit --file WEB-INF/web.xml -o web.xml --insecure
python poc.py -u https://jira.example.com --mode exploit --grab-crowd --insecure
python poc.py --list targets.txt --mode check -j 25 --insecure
python poc.py --list hits.txt --mode exploit --file WEB-INF/web.xml -j 6 --insecure

Outputs: cve_2026_21589_results.jsonl, hits.txt, exploited.txt.

Discovery hints (your assets only)

Self-managed only; exclude SaaS where possible. FOFA/Shodan: Jira/Confluence/Bitbucket login titles, /download/resources/, Atlassian headers — always confirm with --mode check.

Remediation

  1. Apply Atlassian security updates for your product line.
  2. If exploited: rotate Crowd application passwords; review access logs for ..::, %3a%3a, WEB-INF paths.
  3. Restrict admin/management networks; do not expose DC to the open internet without need.

Legal and ethical use

Authorized security testing only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →