Threat Intelligence

Critical Atlassian Flaw Exposes Files on Self-Hosted Servers, With Confusing Fix Details

The Hacker News · 6 Oct 2026
Key Takeaway If you run any self-hosted Atlassian product, block public internet access to it now and upgrade to a fixed version confirmed in Atlassian's official advisory.

Atlassian has disclosed CVE-2026-21589, a critical flaw rated 9.3 out of 10, in 8 of its Data Center products that customers host themselves. An attacker with no login can read specific files in a product's web application root directory. The attacker must already know a file's exact name and path, and cannot list what the directory holds. Atlassian says the risk rises because, in some configurations, that folder may contain sensitive files.

Atlassian's cloud products have already been patched, so cloud customers need to do nothing. For self-hosted customers, all versions before the listed fixed versions are affected, including some that have reached end of life. Atlassian recommends upgrading to a fixed long-term support (LTS) version or later. If you cannot upgrade straight away, take the instance offline if possible. Any instance reachable from the public internet, even one that requires a login, should be restricted from outside access until it is upgraded or a temporary blocking rule is in place.

The published details are not fully consistent. For Crowd's 7.1 branch, the ticket gave both 7.1.7 and 7.1.6 in different places. The CVE record listed different numbers for Crowd and Bamboo, and also marked the older Server editions of several products as affected with no fixed versions, which the advisory did not mention. Check Atlassian's advisory directly before choosing a target version.

Atlassian CVE-2026-21589 Patch Management Data Center Vulnerability

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.