#3
The Hacker News
general
October 06, 2026 at 06:58 UTC
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
By [email protected] (The Hacker News)
AI Summary
A critical unauthenticated file-read vulnerability, CVE-2026-21589 (CVSS 9.3), affects eight Atlassian Data Center products including Confluence, Jira, and Bitbucket, disclosed October 5. Unauthenticated attackers who know a file's exact path can read arbitrary files from the web application root, posing significant risks to self-hosted enterprise deployments that often store sensitive configuration data.
Relevance score: 90.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →