CVE-2026-21589 — Atlassian Data Center Pre-Auth Arbitrary File Read (:: Traversal)
October 8, 2026 · 75 views
Atlassian DC/self-managed (Jira, Confluence, Bitbucket, etc.): atlassian-plugins-webresource unescapeSlashes converts :: to / — ..:: traversal on /download/resources/ reads files under web app root (WEB-INF/web.xml, crowd.properties). CVSS 4.0 9.3 Critical, unauthenticated, read-only not RCE. Python PoC: check/exploit, --grab-crowd, mass -j. Marker POCBIT-21589-OK.
Description
Overview
CVE-2026-21589 — Atlassian Data Center / self-managed products — unauthenticated arbitrary file read inside the Tomcat web application root via atlassian-plugins-webresource (:: → / in Router.unescapeSlashes()).
| | | |---|---| | Products | Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, Fisheye (DC / on-prem) | | Type | Read-only (not write/RCE by itself) | | Auth | None | | CVSS 4.0 | 9.3 Critical | | Verify marker | POCBIT-21589-OK | | Cloud | Patched; PoC targets self-hosted |
Limits: no directory listing; paths must be known; reads stay inside web app root. Optional chain: WEB-INF/classes/crowd.properties → Crowd app credentials (separate impact).
PoC page: https://pocbit.org/pocs/cve-2026-21589
GitHub: murrez/CVE-2026-21589
CVE.org: CVE-2026-21589
Example patched versions
| Product | Patched at or above (examples) | |---------|--------------------------------| | Jira DC | 9.12.40, 10.3.26, 11.3.12 | | Confluence DC | 9.2.26, 10.2.19 | | Bitbucket DC | 9.4.26, 10.2.8, 10.5.1 |
See vendor advisory for full matrix.
Bundled tool (Python 3.10+)
Download cve-2026-21589.py — writes poc.py, requirements.txt.
python cve-2026-21589.py
pip install requests
python poc.py -u https://jira.example.com --mode check
python poc.py -u https://jira.example.com --mode exploit --file WEB-INF/web.xml -o web.xml --insecure
python poc.py -u https://jira.example.com --mode exploit --grab-crowd --insecure
python poc.py --list targets.txt --mode check -j 25 --insecure
python poc.py --list hits.txt --mode exploit --file WEB-INF/web.xml -j 6 --insecure
Outputs: cve_2026_21589_results.jsonl, hits.txt, exploited.txt.
Discovery hints (your assets only)
Self-managed only; exclude SaaS where possible. FOFA/Shodan: Jira/Confluence/Bitbucket login titles, /download/resources/, Atlassian headers — always confirm with --mode check.
Remediation
- Apply Atlassian security updates for your product line.
- If exploited: rotate Crowd application passwords; review access logs for
..::,%3a%3a, WEB-INF paths. - Restrict admin/management networks; do not expose DC to the open internet without need.
Legal and ethical use
Authorized security testing only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- Web appCVE-2026-105844critical
CVE-2026-105844 — Payload CMS Import/Export Plugin Prototype Pollution → ACL Bypass
Payload CMS + @payloadcms/plugin-import-export ≥3.0.0 <3.88.0: POST /api/exports/export-preview fields __proto__.overrideAccess pollutes Object.prototype via getSelect() → overrideAccess on later REST ops, unauthenticated data leak (app-dependent RCE). CWE-1321, CVSS 4.0 9.3 Critical. Fixed 3.88.0 / 4.0.0-canary.27. Python PoC: check/exploit/mass -j, hits.txt & exploited.txt.
- Web appCVE-2026-101894critical
CVE-2026-101894 — @xhmikosr/decompress Symlink-Chain Archive Path Traversal
Node.js @xhmikosr/decompress (and unmaintained decompress): read/write outside output dir via chained symlink archive entries — bypass of CVE-2026-53486 hardening. Fixed in 10.2.2 / 11.1.4; kevva decompress ≤4.2.1 unpatched. CVSS 3.1 9.1 Critical. Python PoC: --lab, lockfile check, evil.tar upload exploit, mass -j.
- Web appCVE-2026-85520critical
CVE-2026-85520 — PrestaShop gmfeed (MyPresta) Unauthenticated Arbitrary File Write → RCE
Google Merchant Center Feed (gmfeed) for PrestaShop ≤2.3.9: unauthenticated arbitrary file write on modules/gmfeed/feed.php when Save-to-file / URL export is enabled — attacker controls filename, path, extension, and body → PHP webshell → RCE. CVSS 9.3 Critical. Fixed in 2.3.10+ (2.4.1+ recommended). Python PoC: check, aggressive probe, exploit with marker stub, mass --list -j.
- WordPressCVE-2026-87902critical
CVE-2026-87902 — WordPress Core get_page_template() Unauthenticated LFI → RCE (PEAR chain)
WordPress core 4.7.0–7.1.1: pagename from POST used in get_page_template() without validate_file(); page-templates/ traversal + PEAR gadget → RCE. GHSA-7hp8-65ch-5whp, CVSS 4.0 9.8, CWE-22. Fixed 7.1.2+ (backports 6.8.10, 7.0.6). Python mass scanner: --check, --rce, --shell. Upstream: MRdark-ops/CVE-2026-87902 (HackfutSecRoot).