Vulnerabilities & Exploits
Atlassian File-Access Bug Reaches Server Secrets Atlassian issued an action-required advisory for CVE-2026-21589 affecting its Data Center products, including Jira Data Center. The flaw is critical, and the vendor is warning administrators to treat it as a security issue, not a routine product notice.
The bug lets a request aimed at the app make the server return a file it should never expose. In plain terms, the application can be abused as a reader for files on the host, so exposed content is not limited to Jira records; it can include configuration and other sensitive local data sitting beside the app.
That puts the blast radius on whatever the server account can read on disk. If a Data Center deployment stores secrets, keys, or config files locally, a compromise can reach outside the application boundary and into the broader host estate.
5 sources · 3h ago
CVE-2026-21589 NVD KEV
Timeline Sources Oct 6 INCIBE-CERT
Acceso arbitrario a archivos en productos de Atlassian
Atlassian ha publicado una vulnerabilidad de severidad crítica que, en caso de ser explotada, podría p
original Oct 6 CSIRT Italia / ACN
Risolta vulnerabilità in prodotti Atlassian
Aggiornamenti di sicurezza risolvono una vulnerabilità con gravità "critica" in diversi prodotti Atlassian.
original Oct 6 The Hacker News
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
Atlassian fixes a critical path traversal in 8 Data Center products that lets unauthenticated attackers read files if exact paths are known.
original Part of the PlainSec briefing for 2026-10-06
Every edition of this story: Atlassian File-Access Bug Reaches Server Secrets
More from today
Vulnerabilities & Exploits
Atlassian File-Access Bug Reaches Server Secrets Atlassian issued an action-required advisory for CVE-2026-21589 affecting its Data Center products, including Jira Data Center. The flaw is critical, and the vendor is warning administrators to treat it as a security issue, not a routine product notice.
The bug lets a request aimed at the app make the server return a file it should never expose. In plain terms, the application can be abused as a reader for files on the host, so exposed content is not limited to Jira records; it can include configuration and other sensitive local data sitting beside the app.
That puts the blast radius on whatever the server account can read on disk. If a Data Center deployment stores secrets, keys, or config files locally, a compromise can reach outside the application boundary and into the broader host estate.
5 sources · 3h ago
CVE-2026-21589 NVD KEV
Timeline Sources Oct 6 INCIBE-CERT
Acceso arbitrario a archivos en productos de Atlassian
Atlassian ha publicado una vulnerabilidad de severidad crítica que, en caso de ser explotada, podría p
original Oct 6 CSIRT Italia / ACN
Risolta vulnerabilità in prodotti Atlassian
Aggiornamenti di sicurezza risolvono una vulnerabilità con gravità "critica" in diversi prodotti Atlassian.
original Oct 6 The Hacker News
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
Atlassian fixes a critical path traversal in 8 Data Center products that lets unauthenticated attackers read files if exact paths are known.
original Part of the PlainSec briefing for 2026-10-06
Every edition of this story: Atlassian File-Access Bug Reaches Server Secrets
More from today