Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
Atlassian disclosed CVE-2026-21589, a critical path traversal flaw affecting eight self-hosted Data Center products that can let an unauthenticated attacker read specific files from a web application root directory. Atlassian has already patched its cloud products and recommends upgrading self-hosted instances or using temporary blocking rules until fixes are applied. #Atlassian #CVE-2026-21589 #Bitbucket #Confluence #JiraSoftware #JiraServiceManagement #Bamboo #Crowd #Crucible #Fisheye

Keypoints

  • CVE-2026-21589 affects eight Atlassian Data Center products.
  • The flaw allows file reads without login access if the exact path is known.
  • Atlassian rated the vulnerability 9.3 and released fixed versions.
  • Cloud products are already patched and require no customer action.
  • Temporary blocking rules are available, but patching is still required.

Read More: https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html