Critical file-access bug found in Atlassian Data Center apps
Atlassian has disclosed a critical security flaw, tracked as CVE-2026-21589, in its self-hosted Data Center products, including Jira, Confluence, and Bitbucket. The vulnerability allows unauthenticated attackers to access specific files within the application’s web root, but they must know the exact file name and location. Atlassian urges administrators to patch affected systems or apply mitigations immediately. There is no evidence yet of active exploitation, according to Atlassian.
- Affects 8 self-hosted Atlassian Data Center products
- Allows unauthenticated file access with known file path
- Cloud services were patched automatically
- No signs of exploitation so far, Atlassian says
- Upgrading or applying mitigations is strongly urged
Sources covering this
More in Cybersecurity
Hackers send extortion message through ASOS app
Hackers took control of ASOS's app notification system and sent a message to users claiming to have breached the company's Snowflake…
ClickFix attacks use browser cache to smuggle payloads
A recent ClickFix campaign is hiding malicious Visual Basic scripts disguised as image files in browser caches on victims' devices,…
Phishing campaign uses fake AI ad tools to steal credentials
Researchers report a phishing operation targeting digital advertising professionals through counterfeit AI tools like ChatGPT, Gemini,…
Nikkei reveals breaches of employee email accounts
Japanese media group Nikkei disclosed that two employee cloud email accounts were breached in separate incidents this year.