CyberSecurity News
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
AI summary
A critical vulnerability has been discovered in 8 Atlassian Data Center products, allowing unauthenticated attackers to read specific files in the web application root directory. The attacker must have prior knowledge of the file's exact name and path to exploit the flaw. Atlassian has disclosed the issue, assigning it a severity rating of 9.3 out of 10. The vulnerability affects products that are hosted by customers themselves, rather than cloud-based versions. Atlassian disclosed the flaw on October 5 and assigned it the identifier CVE-2026-21589. The flaw does not permit attackers to list the directory's contents, only to read files whose names and paths are already known.
Vulnerabilities mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

