Decrypted: The UK Cyber Briefing
Oct 7, 2026 · 4 min · 5 segments
Atlassian has warned of CVE-2026-21589, a critical unauthenticated file-access flaw in its self-hosted Data Center products. No exploitation was reported at disclosure. Also: ASOS's rogue app alert…
What the flaw actually does.
Picture a web application as a building with a public lobby and a locked back office.
The web route is the lobby.
It's the files the server will hand to anyone who asks.
The flaw lets an unauthenticated visitor fetch specific files from inside that web route which were never meant to be handed out.
There's a catch, and it matters.
The attacker has to know the exact file name and path in advance.
They can't ask for a directory listing, so it's less like wandering the corridors and more like requesting a named document from a clerk who's forgotten to check your pass.
In plain terms, how bad this is for you depends on what your instance keeps in places the web server can reach.
The affected products are the data center versions of Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd, plus Crucible and Fisheye.
What the flaw actually does.
Picture a web application as a building with a public lobby and a locked back office.
The web route is the lobby.
It's the files the server will hand to anyone who asks.
The flaw lets an unauthenticated visitor fetch specific files from inside that web route which were never meant to be handed out.
There's a catch, and it matters.
The attacker has to know the exact file name and path in advance.
They can't ask for a directory listing, so it's less like wandering the corridors and more like requesting a named document from a clerk who's forgotten to check your pass.
In plain terms, how bad this is for you depends on what your instance keeps in places the web server can reach.
The affected products are the data center versions of Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd, plus Crucible and Fisheye.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.