# Atlassian discloses file-reading flaw across 8 self-hosted products

_Published Tuesday, October 6, 2026 at 4:06 AM EDT · Security · Latest · Tier 2 — Notable_

![Atlassian discloses file-reading flaw across 8 self-hosted products — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGQge2pd9O29G6qjsswRMYKnpM66wzyEWHOnRljkIZUZpCGVGACovyKIiji1HQ4jZOsypuaveJUBxx0r7-tT-Icd3COeo_prgm0TbMWDJBYFYpWHOC3lBjb8sZo6f2qWPkzeztOAjMW1CjrE_fDe3nWBU2FEOOjUWDpNUbtY1okTyx_iFE7xcI5jxOeiQ/s1700-nu-rw-lo-l85-e365/file.jpg)

Atlassian disclosed a critical vulnerability on October 5 that lets attackers without login access read specific files in 8 Data Center products. The company rated CVE-2026-21589 at 9.3 out of 10 and listed fixed versions. Attackers must know a file's exact name and path; they cannot list directory contents.

The flaw uses specially constructed paths to access files in the folder containing the web application, which may hold sensitive files in some configurations. Atlassian advises restricting outside network access until instances are upgraded or temporary blocking rules are installed. Those rules are limited substitutes for patching. Affected cloud products have already been patched, and cloud customers need no action.

## Sources

- [The Hacker News](https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html)

---
Canonical: https://techandbusiness.org/newswire/HyAmZnji4Z0VTk3dy5Gtg9
Published: 2026-10-06T08:06:34.991Z
Story chronology: 2026-10-05T00:00:00.000Z
Retrieved: 2026-10-06T10:57:54.444Z
Publisher: Tech & Business (techandbusiness.org)
