
Atlassian patches critical unauthenticated file-read flaw across eight self-hosted products
Atlassian disclosed CVE-2026-21589 on October 5, a critical path traversal flaw affecting eight self-hosted Data Center products. The vulnerability allows unauthenticated attackers to read specific files in the web application root directory if they know the exact file path. Atlassian rated the flaw 9.3/10 on the CVSS scale. Cloud versions are already patched, but self-hosted users must upgrade to specific fixed versions or apply temporary mitigations. Atlassian has not confirmed active exploitation but advises users to check logs for suspicious requests.













