Detection Artifact Generator attempts to check if the target is vulnerable to CVE-2026-21589. Detection is implemented for following products:
You need to provide following inputs:
Sample run against vulnerable Jira instance:
Sample run against patched instance:
This script attempts to detect if Jira/Confluence/Bitbucket is vulnerable to CVE-2026-21589 Arbitrary File Read vulnerability.
Full version of affected versions can be found here vendor advisory :
According to the official advisory, patched versions are:
Bitbucket Data Center 9.4.26 10.2.8 10.5.1
Confluence Data Center 9.2.26 10.2.19
Jira Service Management Data Center 5.12.40 10.3.26 11.3.12
Jira Service Management Data Center
Jira Software Data Center 9.12.40 10.3.26 11.3.12
Bamboo Data Center 10.2.24 12.1.12
Crowd Data Center 6.3.7 7.0.3 7.1.7 7.2.4
For the latest security research follow the watchTowr Labs Team
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
