Atlassian warns of critical file-access flaw in Jira, Confluence

Executive Summary

Atlassian has issued a security advisory for a critical vulnerability (CVE‑2026‑21589) that allows attackers to read arbitrary files on servers running its self‑hosted Data Center products. The flaw affects Confluence, Jira, and Bitbucket, enabling unauthorized file access without authentication. The advisory recommends applying the latest patches and updating to the latest versions. Users are urged to review the Atlassian security page for detailed mitigation steps.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-10-06T17:34:59+00:00 - Category: threat-intel

Original Description: Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]

"Those who are free of resentful thoughts surely find peace."

— Buddha
Source: Bleeping Computer