Overview
- Atlassian disclosed the vulnerability, tracked as CVE-2026-21589, on October 5 and rated it 9.3 under CVSS 4.0 in its advisory.
- The flaw is a path traversal that lets an attacker read a specific file in an application's web root if they already know the exact file name and path; it does not allow directory listing or file discovery.
- Atlassian has published fixed releases for all eight affected Data Center products and says its cloud services are patched; administrators who cannot upgrade immediately should restrict external access or apply one of three temporary blocking rules.
- The company says its cloud investigation found no evidence of exploitation but cannot confirm whether self-hosted Data Center instances were accessed and tells customers to search access logs for URL-encoded '..' traversal patterns.
- Reporters flagged inconsistencies in Atlassian's CVE record about version numbers and Server editions, and past exploited Jira path-traversal flaws that CISA cataloged heighten the need for prompt patching and log review.