Critical Atlassian Flaw Exposes File Access in 8 Products
Original source
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
The Hacker News →A critical path traversal flaw in 8 Atlassian Data Center products allows unauthenticated attackers to read known files in the web application root directory. The vulnerability, CVE-2026-21589, rated 9.3 out of 10, affects specific versions of products like Crowd, Bamboo, Confluence, and others. Atlassian has released fixed versions for each product and advises customers to upgrade immediately or apply temporary blocking rules if upgrading is not possible. The flaw could expose sensitive files depending on the server configuration, and past exploitation of similar flaws has been documented.
Read the full article
Continue reading at The Hacker News →This is an AI-generated summary. Read the original for the full story.