Vulnerability Management, DevSecOps, Data Security

Atlassian urges datacenter product users to patch critical file access vulnerability

Atlassian has issued an urgent call to action for users of its datacenter products to apply patches immediately following the discovery of a critical vulnerability. The company is advising all users to upgrade their software to prevent potential unauthorized access to sensitive files, with further coverage provided by The Register.

The vulnerability, identified as CVE-2026-21589 with a severity rating of 9.3, affects the datacenter versions of multiple Atlassian products, including Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye. An unauthenticated attacker can exploit this flaw to access specific files within the web application's root directory. While attackers need to know the exact filename and path, and cannot view directory contents, the risk increases if sensitive files are present.

Atlassian recommends that instances accessible via the public internet be restricted from external network access until patching can be completed. Users who have migrated to Atlassian's cloud offerings are not affected, as these versions have already been secured. This situation underscores Atlassian's strategic shift towards cloud-based solutions and away from server and datacenter software.

Source: The Register

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds