The Australian collaboration software company sent users an email on Monday with the subject line "Action required," directing them to a security bulletin. The bulletin details a flaw that, according to Atlassian, "allows an unauthenticated attacker to access specific files within the web application root directory in affected versions." The company cautioned that in some configurations sensitive files may be present, increasing the risk.
Some factors limit the danger: attackers must know the exact filename and path, and the vulnerability does not allow directory listing. Atlassian has released updated versions of all affected products. For organisations that cannot immediately apply the patch, the company recommends removing instances from the public internet. "Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action," the advisory warned.
Users who have already migrated from Atlassian's datacenter products to the Atlassian cloud are unaffected, as the flaw was fixed in Atlassian's own SaaS environment. This outcome supports the company's strategic decisions in 2020 and last year to phase out server and datacenter products in favour of cloud migration, although Atlassian has acknowledged the transition has not always been easy, pointing to an earlier migration tool it described as worse than its predecessor.
The advisory comes against a backdrop of significant change at the company. Atlassian cut ten percent of staff in March 2026, a period when its share price was falling amid suggestions it might be vulnerable to the "SaaSPocalypse" theory that AI would replace business software. The company's share price has since tripled, suggesting greater investor confidence in its strategy of using AI to enhance workflows.