Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Atlassian patches critical flaw in eight self-hosted products

Published 7 October 2026

Atlassian has disclosed and patched a critical vulnerability that could let unauthenticated attackers read specific files from the web application roots of eight self-hosted Data Center products. The company rated the flaw, tracked as CVE-2026-21589, 9.3 out of 10 under CVSS 4.0 and urged customers to upgrade affected installations or restrict their external access while applying temporary safeguards. The affected products are Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. Atlassian’s advisory says all versions before the product-specific fixed releases are affected. The flaw does not require a login, but an attacker must know the exact name and path of a target file. It does not allow directory contents to be listed. Atlassian warned that some configurations may store sensitive files in the affected locations, potentially increasing the risk. The company described the 9.3 score as its own assessment and advised customers to evaluate how the issue applies to their systems.

Now playing
0:00 / 0:00