Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

Cybersecurity · October 7, 2026

Cybersecurity·thehackernews.com

Atlassian has disclosed CVE-2026-21589, a critical flaw affecting eight self-hosted Data Center products that lets an attacker with no account access retrieve specific files sitting in a product's web root. The catch for defenders is small comfort: exploitation requires already knowing the exact file name and path, since directory listing isn't possible. Atlassian rated the issue 9.3 out of 10 and disclosed it on October 5, 2026.

// source: thehackernews.com ↗

← Back to Blog