Critical Atlassian Data Center Path Traversal Fixes
🔒 Atlassian disclosed CVE-2026-21589, a critical path traversal vulnerability in eight Data Center products that allows unauthenticated attackers who know a file's exact path to read files from the web application root. The flaw, rated 9.3 CVSS v4.0, affects on-premises deployments and has fixed versions listed for each product; cloud offerings have been patched. Atlassian advises offlineing or restricting internet access for instances that cannot be upgraded and provides temporary WAF or server-level blocking rules as mitigations.
