AI Weekly Malaysia

Back to items Summaries

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

ID
32194
Status
summarized
Published
06 Oct 2026, 2:58 PM
Fetched
06 Oct 2026, 5:23 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
6.5
Created
06 Oct 2026, 5:24 PM
Tags
Audience
developerssaas_startup_founders

What happened

Atlassian disclosed CVE-2026-21589 on October 5 and rated it 9.3/10; it lets unauthenticated attackers read files in the web application root directory across eight self-hosted Data Center products if they already know a file's exact name and path, and cannot list the directory. Affected products include Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye, with fixed versions listed as of October 6. Atlassian cloud products are already patched and need no action, but the CVE record has version discrepancies for Crowd and Bamboo versus Atlassian's ticket.

Why it matters

If your team self-hosts any affected Data Center product below the fixed versions—for example Bitbucket before 9.4.26/10.2.8/10.5.1 or Confluence before 9.2.26/10.2.19—upgrade to a fixed LTS or later; if you cannot, restrict public network access or take the instance offline. Cloud users should not spend time on this, but self-hosted admins should verify the Crowd and Bamboo version numbers against Atlassian's ticket because the CVE record lists conflicting values.

Discussion angle

How should self-hosted Atlassian admins handle the CVE-record discrepancies for Crowd and Bamboo when deciding whether to emergency-patch or isolate instances?

Top