importantSYS.SOURCE: The Hacker News• 2026-10-06T12:28:56+05:30
Critical Path Traversal Vulnerability in 8 Atlassian Products Allows Unauthenticated File Access
A critical path traversal vulnerability (CVE-2026-21589) in 8 Atlassian Data Center products allows unauthenticated attackers to read specific files if they know exact paths, with mitigations and fixed versions provided. The flaw affects self-hosted instances, requiring immediate patching or temporary network restrictions.
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory.
The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and
*** END OF TRANSMISSION ***