RC RANDOM CHAOS

Critical Atlassian Flaw Exposes File Access in 8 Products

· via The Hacker News

Original source

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

The Hacker News →

A critical path traversal flaw in 8 Atlassian Data Center products allows unauthenticated attackers to read known files in the web application root directory. The vulnerability, CVE-2026-21589, rated 9.3 out of 10, affects specific versions of products like Crowd, Bamboo, Confluence, and others. Atlassian has released fixed versions for each product and advises customers to upgrade immediately or apply temporary blocking rules if upgrading is not possible. The flaw could expose sensitive files depending on the server configuration, and past exploitation of similar flaws has been documented.

Read the full article

Continue reading at The Hacker News →

This is an AI-generated summary. Read the original for the full story.