Atlassian patches critical file-access flaw across eight self-hosted products
Cyber Security · Wednesday, October 7, 2026 · 11 sources

Atlassian patches critical file-access flaw across eight self-hosted products

Atlassian has issued fixes for CVE-2026-21589, a critical vulnerability in eight self-hosted Data Center products, including Jira, Confluence and Bitbucket. An unauthenticated attacker can read specific files in an application’s web root, but must know each file’s exact path; Atlassian rates the flaw 9.3 out of 10. Cloud products have been patched, with no customer action required.

Bottom line — Atlassian says self-hosted customers should patch each affected product or restrict access until they can.

Go deeper 5

  1. Atlassian says the flaw affects all versions before the relevant fixed releases and warns that some configurations may store sensitive files in the web root.

  2. The vulnerability does not let attackers list directory contents, according to Atlassian.

  3. For installations that cannot be patched immediately, Atlassian recommends restricting external access; temporary WAF or server-level rules are also available.

  4. Atlassian advises security teams to review access logs for traversal patterns, decoding requests up to twice to catch encoded variants.

  5. BleepingComputer reports Atlassian has no evidence that the flaw is being exploited, but cannot confirm whether individual customer instances have been affected.

Read the reporting 11

dstld. Your daily news summary designed to surface the news that matters from a European perspective. Curated by humans, summarized by AI - always with links back to the original reporting.

Links · Contact
Popular topics · WorldEuropeGamesAI
Last generated: Oct 7, 6:51 AM UTC by wreetco

dstld. Your daily news summary designed to surface the news that matters from a European perspective. Curated by humans, summarized by AI - always with links back to the original reporting.

Links · Contact
Popular topics · WorldEuropeGamesAI
Last generated: Oct 7, 6:51 AM UTC by wreetco