Atlassian says an attacker has to know the exact filename, which for an off-the-shelf product everybody does
2026-10-07Security
CVE-2026-21589 scores 9.3 and lets an unauthenticated attacker read files from the web application root across eight Data Center products. The advisory notes they cannot list directories and must know the exact path. For software anyone can download and install, that is a description of the attack, not a limit on it.