Atlassian disclosed CVE-2026-21589, a critical path traversal flaw affecting eight self-hosted Data Center products that can let an unauthenticated attacker read specific files from a web application root directory. Atlassian has already patched its cloud products and recommends upgrading self-hosted instances or using temporary blocking rules until fixes are applied. #Atlassian #CVE-2026-21589 #Bitbucket #Confluence #JiraSoftware #JiraServiceManagement #Bamboo #Crowd #Crucible #Fisheye
Keypoints
- CVE-2026-21589 affects eight Atlassian Data Center products.
- The flaw allows file reads without login access if the exact path is known.
- Atlassian rated the vulnerability 9.3 and released fixed versions.
- Cloud products are already patched and require no customer action.
- Temporary blocking rules are available, but patching is still required.
Read More: https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html