Particle.news

Atlassian Data Center Flaw Lets Unauthenticated Requests Read Specific Files

Cloud services have been patched, but Atlassian urges immediate upgrades or temporary blocking rules because it cannot confirm whether self-hosted instances were accessed.

Overview

  • Atlassian disclosed the vulnerability, tracked as CVE-2026-21589, on October 5 and rated it 9.3 under CVSS 4.0 in its advisory.
  • The flaw is a path traversal that lets an attacker read a specific file in an application's web root if they already know the exact file name and path; it does not allow directory listing or file discovery.
  • Atlassian has published fixed releases for all eight affected Data Center products and says its cloud services are patched; administrators who cannot upgrade immediately should restrict external access or apply one of three temporary blocking rules.
  • The company says its cloud investigation found no evidence of exploitation but cannot confirm whether self-hosted Data Center instances were accessed and tells customers to search access logs for URL-encoded '..' traversal patterns.
  • Reporters flagged inconsistencies in Atlassian's CVE record about version numbers and Server editions, and past exploited Jira path-traversal flaws that CISA cataloged heighten the need for prompt patching and log review.