Skip to main content

Share story

Security

Atlassian discloses file-reading flaw across 8 self-hosted products

Atlassian discloses file-reading flaw across 8 self-hosted products Image: Primary
Atlassian disclosed a critical vulnerability on October 5 that lets attackers without login access read specific files in 8 Data Center products. The company rated CVE-2026-21589 at 9.3 out of 10 and listed fixed versions. Attackers must know a file's exact name and path; they cannot list directory contents. The flaw uses specially constructed paths to access files in the folder containing the web application, which may hold sensitive files in some configurations. Atlassian advises restricting outside network access until instances are upgraded or temporary blocking rules are installed. Those rules are limited substitutes for patching. Affected cloud products have already been patched, and cloud customers need no action.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Capital
AI Capital

DeepSeek reportedly nears funding of at least 80 billion yuan

DeepSeek is close to raising at least 80 billion yuan in a new funding round, Bloomberg reported Tuesday, with Tencent and CATL committing some of the largest sums. The AI lab initially sought about 50 billion yuan; demand increas...

Security Capital
Security Capital

Hadrian raises $40m to expand automated security testing

Amsterdam cybersecurity startup Hadrian has raised $40m in a round co-led by Forgepoint Capital International and Smartfin, bringing its total funding to $65m. The company says it will expand across Europe, the Middle East, Africa...

Security
Security

Dell urges System Update patch for flaw enabling root access

Dell urged customers to update its System Update tool after identifying a critical vulnerability that could let an unauthenticated remote attacker execute code with root privileges on vulnerable PowerEdge servers. SecurityAffairs ...

AI Policy
AI Policy

Pentagon says it has ended use of Anthropic products

The Pentagon has completed its phase-out of Anthropic products, the BBC reported, citing the US Department of Defense. The removal followed a dispute over Anthropic's insistence on contractual restrictions against mass surveillanc...