hacker-news · Crawled Oct 6, 2026

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

Read original article ↗

AI Summary

A critical path traversal vulnerability, CVE-2026-21589, affects 8 self-hosted Atlassian Data Center products, allowing unauthenticated attackers to read specific files in the web application root directory if they know the exact filename and path. The vulnerability is rated 9.3 on the CVSS v4.0 scale due to its network accessibility and high confidentiality impact. Atlassian has released fixed versions for affected Data Center products and applied patches to its cloud instances, while advising self-hosted customers to either upgrade or implement temporary mitigations such as WAF rules or Tomcat rewrite rules to block malicious URL patterns containing '..' adjacent to path separators.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.