news.mlab.sh
Back to the feed
vulnerability

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

HighCVSS 9.3EPSS 100%
Image: The Hacker News
Summary

A critical vulnerability (CVE-2026-21589) in eight Atlassian Data Center products allows unauthenticated attackers to read specific files in the web application root directory. The vulnerability is similar to a previously exploited path traversal flaw (CVE-2021-26086), and Atlassian advises customers to check access logs for suspicious activity.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Also covered by 6 other source(s)

Report an error
Confirmed errors are fixed and listed on /corrections.