Atlassian discloses critical file-access flaw affecting eight products

First reported by The Hacker News at · Updated · 3 sources

The vulnerability, CVE-2026-21589, lets attackers without login credentials read specific files in the web application root directory of affected self-hosted Data Center products. It carries a severity score of 9.3 out of 10. Attackers must know the exact filename and path and cannot list directory contents, according to The Hacker News.

  • Affected products include Jira, Confluence and Bitbucket.
  • Atlassian disclosed the flaw on October 5, according to The Hacker News.

Covered by 3 publishers within 11 hours of the first report.

Reporting3

The Hacker News Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products · info@thehackernews.com (The Hacker News)
BleepingComputer Atlassian warns of critical file-access flaw in Jira, Confluence · Bill Toulas

Related

Topics Data centers