Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
Security

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

The Hacker News · Oct 06, 2026

Back to News
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
Security October 6, 2026

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.