Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published • loading... • Updated

Atlassian Warns of Critical File-Access Flaw in Jira, Confluence

The 9.3-rated flaw lets unauthenticated attackers reach specific files, and Atlassian says cloud customers are already patched.

Summary by BleepingComputer
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket.

10 Articles

The RegisterThe Register
Reposted by
IT Security News - cybersecurity, infosecurity newsIT Security News - cybersecurity, infosecurity news
Center

Atlassian warns of critical file access flaw in its datacenter products

Tells users ‘action required’ – but maybe don’t make that action a Jira ticket, because it has this bug

·London, United Kingdom
Read Full Article

Atlassian asked users of its Datacenter products to urgently install an update to close a vulnerability without authentication, rated 9.3, which allows access to specific files within the root of the web application.

Global Security Mag OnlineGlobal Security Mag Online
Reposted by
Global Security Mag OnlineGlobal Security Mag Online

Multiple vulnerabilities have been discovered in Atlassian products. They allow an attacker to cause a breach of data confidentiality.

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The Register broke the news in London, United Kingdom on Tuesday, October 6, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal