Vulnerabilities · 3h ago
Atlassian issued an action-required advisory for CVE-2026-21589 affecting its Data Center products, including Jira Data Center. The flaw is critical, and the vendor is warning administrators to treat it as a security issue, not a routine product notice.
The bug lets a request aimed at the app make the server return a file it should never expose. In plain terms, the application can be abused as a reader for files on the host, so exposed content is not limited to Jira records; it can include configuration and other sensitive local data sitting beside the app.
That puts the blast radius on whatever the server account can read on disk. If a Data Center deployment stores secrets, keys, or config files locally, a compromise can reach outside the application boundary and into the broader host estate.
4 sources covering this story
Risolta vulnerabilità in prodotti Atlassian
Aggiornamenti di sicurezza risolvono una vulnerabilità con gravità "critica" in diversi prodotti Atlassian.
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
Atlassian fixes a critical path traversal in 8 Data Center products that lets unauthenticated attackers read files if exact paths are known.
Atlassian warns of critical file access flaw in its datacenter products
Tells users ‘action required’ – but maybe don’t make that action a Jira ticket, because it has this bug
CVE-2026-21589: Atlassian Bitbucket
This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center.
Part of the PlainSec briefing for 2026-10-06