Atlassian warns of critical file-access flaw in Jira, Confluence
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]
Sources
- T1Atlassian warns of critical file-access flaw in Jira, ConfluenceBleepingComputer
Vulnerabilities
Why this score
| Signal | Points |
|---|---|
| cvss critical — 9.3 | 20 |
| widely deployed | 15 |