{
  "id": 12313792,
  "title": "Atlassian warns of critical file access flaw in its datacenter products",
  "url": "https://urgent.news/2026/10/06/atlassian-warns-of-critical-file-access-flaw-in-its-datacenter",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-06T04:20:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/10/06/atlassian-warns-of-critical-file-access-flaw-in-its-datacenter-products/5301284"
  },
  "original_language": "en",
  "account": "Atlassian has issued an urgent warning to users of its datacenter products, urging them to patch the software to prevent attackers from accessing their files. The company has identified a serious security flaw, CVE-2026-21589, a 9.3-rated arbitrary file access vulnerability, affecting several of its products including Bitbucket, Confluence, and Jira Software. This vulnerability allows an unauthenticated attacker to access specific files within the web application root directory, potentially exposing sensitive data under certain configurations. However, the attacker must know the exact filename and path to exploit this vulnerability, and it does not provide access to directory contents. Atlassian has released updated versions of its software, but users have until they can act to upgrade or remove their instances from the internet, if possible. The company advises those unable to patch to restrict external network access to their instances. Users who migrated their operations to Atlassian's cloud services are unaffected, as the cloud version already includes the fix. Atlassian's decision to transition users from their low-end server products to its cloud platform in 2020 appears to have been justified, as its share price has tripled since the implementation, suggesting investor confidence in the company’s strategy to utilize AI to enhance workflow capabilities.",
  "summary": "Tells users ‘action required’ – but maybe don’t make that action a Jira ticket, because it has this bug",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Atlassian warns of critical file access flaw in its datacenter products",
        "url": "https://urgent.news/2026/10/06/atlassian-warns-of-critical-file-access-flaw-in-its-datacenter-12316048",
        "published": "2026-10-06T04:20:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}