Urgent.News

What's breaking now, across thousands of outlets.

Tech

Eight Atlassian Data Center Products Share One File-Read Flaw and One Patch Clock

TL;DR Atlassian Data Center is the self-hosted edition of Atlassian's collaboration software, the version a company runs on its own servers, and its eight members cover code hosting, project tracking, a team wiki, a build server and a central user directory. Atlassian published an advisory on 5 October 2026 for CVE-2026-21589, rated 9.3, that lets an unauthenticated attacker read specific files…

Atlassian Data Center, a self-hosted version of the company's collaboration software, has a shared file-read flaw affecting eight of its products. Published on October 5, 2026, the vulnerability (CVE-2026-21589) allows an unauthenticated attacker to read specific files inside the web application root directory, rated at a critical severity level of 9.3 on the CVSS scale.

The flaw exists because all eight products share a web-resource library, and the exploit path utilizes a double colon sequence to perform directory traversal via plugin resource endpoints. The initial proof of concept was shared on October 7, and within hours, honeypot networks recorded exploitation attempts.

Affected products include Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and FishEye. All versions released before the fixed releases are vulnerable. The shared library at fault, "atlassian-plugins-webresource," version 6.0.7 to 6.0.8, replaces a double colon with a forward slash, creating a directory traversal attack path.

In Crowd-integrated deployments, the vulnerability can lead to credential access, enabling attackers to create a user, elevate privileges to administrator, and gain control of the systems that hold source repositories, internal documentation, and identity records.

Customers must review access logs for the traversal pattern to detect the issue, applying temporary mitigations such as WAF or proxy rules, Tomcat RewriteValve rules, and urlrewrite.xml rules for Bitbucket. Atlassian cannot confirm if an individual instance was affected, placing the detection responsibility on the customer. Detection involves identifying specific request patterns, such as two dots next to a forward slash, backslash, or double colon, including URL-encoded forms.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

I Published 10 Free MCP Servers for Japanese Data (Prices, Sweepstakes, Fuel, TCG) — Here's the Full List

If you build AI agents that need real Japanese data , you've probably hit the same wall I did: Japanese e-commerce, price indices, government datasets, and local marketplaces are scattered across…

  • Author built 10 free MCP servers aggregating Japanese data sources
  • mlit-property-prices-mcp server provides official land-transaction price dataset
  • Servers available for free connection via Smithery URLs or connection snippets

More from Friday 9 October →