Atlassian says CVE-2026-21589 affects all versions of eight self-hosted products. An unauthenticated attacker can read specific files when the exact path is known. Atlassian found no exploitation. Self-hosted customers should upgrade or restrict external access until patched.