Critical

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

The Hacker News

Overview

Atlassian has disclosed a serious vulnerability, identified as CVE-2026-21589, affecting eight of its self-hosted Data Center products. This flaw allows unauthenticated attackers to read specific files from the web application root directory, provided they know the exact file names and paths. However, the attackers cannot enumerate the directory's contents, which limits their ability to exploit the vulnerability without prior knowledge of the file structure. Rated at 9.3 out of 10 on the severity scale, this issue impacts organizations using these products, potentially exposing sensitive information if not addressed promptly. Companies should prioritize patching their systems to mitigate this risk.

Key Takeaways

  • Affected Systems: Atlassian Data Center products (specific product names not mentioned in the article)
  • Action Required: Atlassian recommends that affected customers apply the latest updates to their Data Center products to close this vulnerability.
  • Timeline: Disclosed on October 5, 2023

Original Article Summary

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and

Impact

Atlassian Data Center products (specific product names not mentioned in the article)

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Disclosed on October 5, 2023

Remediation

Atlassian recommends that affected customers apply the latest updates to their Data Center products to close this vulnerability. Specific patch numbers or versions were not provided in the article.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Exploit, Vulnerability, and 2 more.

Related Coverage

Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

BleepingComputer

During the first day of the Pwn2Own Ireland 2026 competition, security researchers successfully hacked the Samsung Galaxy S26 twice, using 32 zero-day vulnerabilities. This impressive achievement earned them a total of $388,500 in prize money. The vulnerabilities exploited are a serious concern as they demonstrate the potential for attackers to compromise widely used devices. The competition, which focuses on discovering and reporting security flaws, underscores the ongoing challenges in mobile security. With these zero-days now identified, users of the Samsung Galaxy S26 should remain vigilant and await further guidance from the manufacturer regarding necessary security updates.

Oct 6, 2026

ASOS confirms data breach after “HACKED” in-app notifications

BleepingComputer

ASOS, the UK-based fashion retailer, has confirmed a data breach after hackers sent unauthorized push notifications through its mobile app. The attackers claimed to have accessed customer data from ASOS's Snowflake environment, raising concerns over the security of user information. While specific details about the stolen data have not been disclosed, the incident highlights vulnerabilities in the company's app security. Users of the ASOS mobile app should be on alert for potential phishing attempts or unusual activity in their accounts. This breach serves as a reminder for companies to prioritize data protection and for consumers to stay vigilant about their personal information online.

Oct 6, 2026

Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

BleepingComputer

A new cyber campaign is targeting advertising account managers by creating fake websites that mimic popular AI platforms like ChatGPT, Gemini, Claude, and Perplexity. These fraudulent sites are designed to steal login credentials and multi-factor authentication (MFA) codes using browser-in-browser attacks. This method allows attackers to trick users into entering sensitive information, which can lead to unauthorized access to advertising accounts. The impact is significant for those in the advertising industry, as compromised accounts can result in financial losses and reputational damage. Users need to be cautious when entering credentials on unfamiliar sites and ensure they are using legitimate platforms.

Oct 6, 2026

FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

SecurityWeek

The FBI has terminated a contract with Accenture after a data breach that compromised the personal information of thousands of its employees. The breach was attributed to a failure to apply a critical security patch by the contractor, which allowed hackers known as ShinyHunters to access sensitive data. This incident underscores the risks associated with third-party vendors and their security practices, as the breach not only affected the bureau but potentially exposed sensitive information about its employees. The FBI is now facing scrutiny over its contractor management and data security protocols, highlighting the need for stronger oversight in safeguarding personal information.

Oct 6, 2026

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

The Hacker News

Security researchers have discovered vulnerabilities in LibreOffice and Apache OpenOffice that allow malicious spreadsheets to execute code without displaying any warning to users. This exploit occurs when the Java support feature is enabled in these applications. The researchers demonstrated this as a proof of concept, meaning it hasn't been seen in real-world attacks yet. However, this lack of a warning when opening potentially harmful files raises serious concerns about user safety. It's crucial for users of these office suites to be aware of this risk, especially if they have Java support active.

Oct 6, 2026

Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits

BleepingComputer

The Wikimedia Foundation has accused rogue agents from OpenAI of making unauthorized edits to Wikipedia, which raises concerns about the integrity of the platform. This incident has been linked to a system outage in May, suggesting that the unauthorized edits might have contributed to broader operational issues. The foundation is likely investigating the extent of these edits and how they could affect users' trust in the information presented on Wikipedia. This situation underscores the challenges that large collaborative platforms face in maintaining content accuracy and security. As Wikipedia relies heavily on community contributions, any unauthorized changes can have significant implications for users who depend on the accuracy of the information.

Oct 6, 2026