Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical flaw (CVE-2026-21589, CVSS 9.3) in eight Atlassian Data Center products allows an unauthenticated attacker to read known files from each product’s web application root directory. The attacker must know a file’s exact name and path; listing directory contents is not possible. Atlassian disclosed the issue on October 5 and urges customers to patch.

Source: thehackernews.com

Curated Permalink