Artefacto de detección en Python que comprueba instancias de Atlassian Jira, Confluence y Bitbucket en busca de la vulnerabilidad de lectura arbitraria de archivos CVE-2026-21589.
CVE-2026-21589 - Lectura Arbitraria de Archivos en Jira/Confluence/Bitbucket
Detection Artifact Generator intenta comprobar si el objetivo es vulnerable a CVE-2026-21589. La detección está implementada para los siguientes productos:
Debes proporcionar las siguientes entradas:
-H - host objetivo.Ejecución de ejemplo contra una instancia de Jira vulnerable:
$ python3 watchTowr-vs-Atlassian-CVE-2026-21589.py -H http://jira.lab.local:8080
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-Atlassian-CVE-2026-21589.py
(*) CVE-2026-21589 - Jira/Confluence/Bitbucket Arbitrary File Read Detection Artifact Generator
- Piotr | Sonny | Yordan of watchTowr (@watchTowrcyber)
[+] Starting CVE-2026-21589 DAG
[+] Attempting to send payloads for Jira, Confluence and Bitbucket
[+] Found VULNERABLE Jira instance
Ejecución de ejemplo contra una instancia parcheada:
$ python3 watchTowr-vs-Atlassian-CVE-2026-21589.py -H http://jirapatch.lab.local:8080
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-Atlassian-CVE-2026-21589.py
(*) CVE-2026-21589 - Jira/Confluence/Bitbucket Arbitrary File Read Detection Artifact Generator
- Piotr | Sonny | Yordan of watchTowr (@watchTowrcyber)
[+] Starting CVE-2026-21589 DAG
[+] Attempting to send payloads for Jira, Confluence and Bitbucket
[-] Unknown response - probably NOT VULNERABLE
Este script intenta detectar si Jira/Confluence/Bitbucket es vulnerable a la vulnerabilidad de Lectura Arbitraria de Archivos CVE-2026-21589.
La versión completa de las versiones afectadas se puede encontrar aquí vendor advisory:
Según el aviso oficial, las versiones parcheadas son:
Bitbucket Data Center
Confluence Data Center
Jira Service Management Data Center
Jira Software Data Center
Bamboo Data Center
Crowd Data Center
Crucible
Fisheye
Para conocer las últimas investigaciones de seguridad, sigue al equipo de watchTowr Labs