Atlassian Patches Critical Arbitrary File Access Vulnerability Across Multiple Products
Atlassian has disclosed and patched a critical arbitrary file access vulnerability, identified as CVE-2026-21589 with a CVSS score of 9.3, affecting eight of its products including Jira, Confluence, and Bitbucket. The flaw allows unauthenticated attackers to access specific files within an affected application's web root directory, although it requires knowledge of the exact file name and path. Atlassian urges customers to apply patches immediately.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.