Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
Atlassian disclosed CVE-2026-21589 on Oct. 5, a critical flaw (CVSS 9.3) affecting eight self-hosted Data Center products that lets an unauthenticated attacker read specific files in each product’s web application root. The attacker must already know a file’s exact name and path and cannot list directory contents, The Hacker News reports.