Vulnerabilities · 3h ago

Atlassian File-Access Bug Reaches Server Secrets

Atlassian issued an action-required advisory for CVE-2026-21589 affecting its Data Center products, including Jira Data Center. The flaw is critical, and the vendor is warning administrators to treat it as a security issue, not a routine product notice.

The bug lets a request aimed at the app make the server return a file it should never expose. In plain terms, the application can be abused as a reader for files on the host, so exposed content is not limited to Jira records; it can include configuration and other sensitive local data sitting beside the app.

That puts the blast radius on whatever the server account can read on disk. If a Data Center deployment stores secrets, keys, or config files locally, a compromise can reach outside the application boundary and into the broader host estate.

CVE-2026-21589

NVD KEV

Timeline

Sources

4 sources covering this story

Entities

Part of the PlainSec briefing for 2026-10-06

Editions

Related stories