# Atlassian Data Center flaw exposes files unauthenticated

Published: 2026-10-06 · Severity: routine
Canonical: https://vorant.io/reports/ed183bb1-cce5-5881-b82a-0755114a7072/atlassian-data-center-flaw-exposes-files-unauthenticated

> An unauthenticated arbitrary file access flaw (CVE-2026-21589, CVSS 9.3) affects multiple Atlassian Data Center products; patches are available.

NCSC-NL published an advisory describing a file disclosure vulnerability affecting Atlassian's Data Center product line, including Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible and Fisheye. The flaw, tracked as CVE-2026-21589 and rated CVSS v4 9.3, allows unauthenticated attackers to access specific files within the web application's root directory, provided they know the exact file path and name. This could expose sensitive files and configuration data, posing a confidentiality risk to affected deployments.

Atlassian has released patched versions for the affected products. The advisory does not indicate evidence of active exploitation in the wild, but given the breadth of affected products and the high CVSS score, organizations running any of the listed Atlassian Data Center products should prioritize applying the vendor patches. Defenders should inventory Data Center deployments across all listed product families and verify patch status, as exploitation requires no authentication and only knowledge of file paths, which could be enumerated or guessed in some configurations.

## Mentioned in this report

- Vulnerabilities: CVE-2026-21589

## Detection guidance (public sample)

### Web Request for Atlassian Application Config or WEB-INF Files Returning 200

ATT&CK: T1005

Successful HTTP requests to WEB-INF or Atlassian configuration files in the web root, consistent with unauthenticated file disclosure attempts against Data Center products. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Web Request for Atlassian Application Config or WEB-INF Files Returning 200
id: 394aa68b-ec2d-57d4-af4b-4fdb2801bdc5
status: experimental
description: Detects successful (HTTP 200) web requests that directly fetch WEB-INF
  contents or well-known Atlassian configuration files from the web application root.
  This is consistent with unauthenticated file disclosure such as CVE-2026-21589 in
  Atlassian Data Center products (Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible,
  Fisheye). The rule keys on the sensitive file path pattern and a successful response,
  not on any campaign-specific value. Tune to the web or proxy log source that fronts
  the Atlassian application.
references:
- https://advisories.ncsc.nl/2026/ncsc-2026-0402.html
tags:
- attack.collection
- attack.t1005
- cve.2026-21589
logsource:
  category: webserver
detection:
  selection_path:
    cs-uri-stem|contains:
    - /WEB-INF/
    - /dbconfig.xml
    - /confluence.cfg.xml
    - /cwd.cfg.xml
    - /crowd.cfg.xml
    - /seraph-config.xml
    - /jira-config.properties
    - /bitbucket.properties
  selection_status:
    sc-status: 200
  condition: selection_path and selection_status
falsepositives:
- Authorized vulnerability scanners or penetration tests probing Atlassian hosts
- Application deployment or health-check tooling that legitimately fetches static
  resources under a WEB-INF-like path
level: medium
author: Vorant
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0402.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ed183bb1-cce5-5881-b82a-0755114a7072/atlassian-data-center-flaw-exposes-files-unauthenticated.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
