Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

Atlassian has disclosed a critical security vulnerability, CVE-2026-21589, affecting eight self-hosted Data Center products. The flaw allows unauthenticated attackers to read sensitive files, prompting the company to urge immediate patching or network isolation.
Why it matters
This vulnerability poses a high risk to enterprise security, potentially exposing sensitive data for organizations relying on self-hosted Atlassian infrastructure.
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory.
The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw , CVE-2026-21589 , on October 5, rated it 9.3 out of 10, and listed a fixed version for each product.
The web application root directory is the folder on the server that holds the web application itself. In some configurations, it may contain sensitive files, which raises the risk, according to Atlassian.
Atlassian's cloud products affected by the flaw have already been patched, and cloud customers do not need to take any action.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in