Atlassian warns of critical file-access flaw in Jira, Confluence
Teaser from the source
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]
This is the RSS-feed teaser. Read the full article at the original source.
Read at BleepingComputer →Linked advisories
- CVE-2026-21589Sicherheitsluecke -- CVE-2026-21589
- CVE-2026-21589Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye und Jira): Schwachstelle ermöglicht Offenlegung von Informationen
- CVE-2026-21589h3.
- CVE-2026-21589Security Advisory 2026-015 — Critical Vulnerability in Multiple Atlassian Products
More on file-access
Other advisories
- osv:CVE-2026-73653noneVitest: Browser Mode provider commands bypass the file-access permission gate
- CVE-2026-73653none@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
- osv:CVE-2026-40604noneClearanceKit: opfilter system extension can be suspended or signalled by a root process, disabling file-access policy enforcement
- CVE-2026-22444noneApache Solr: Insufficient file-access checking in standalone core-creation requests
- CVE-2026-22444noneApache Solr: Insufficient file-access checking in standalone core-creation requests
- osv:CVE-2026-22444noneApache Solr: Insufficient file-access checking in standalone core-creation requests
ID