CVE-2021-26085
KEV ransomware PoC largeUnauthenticated Arbitrary File Read in Atlassian Confluence Server
CISA: Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability
CVE-2021-26085 is a pre-authorization arbitrary file read (CWE-425) in Atlassian Confluence Server, meaning an attacker needs no credentials to exploit it. It is triggered by sending crafted remote requests to Confluence's /s/ endpoint, which serves static resources, causing the server to expose restricted resources and files outside what an unauthenticated user should reach. Successful exploitation grants read access to arbitrary files on the Confluence host, which can expose configuration files, credentials, and other sensitive data. All unpatched Atlassian Confluence Server deployments are affected, particularly instances reachable from the internet. The flaw is listed in the CISA KEV catalog (added 2022-03-28) with known ransomware use, and its 99.9% EPSS probability of exploitation within 30 days indicates very widespread targeting, though no public PoC is cataloged.
What to do: Apply Atlassian's official updates for CVE-2021-26085 per the vendor's instructions as required by the CISA KEV listing, prioritizing internet-facing Confluence servers. Review access logs for suspicious requests to the /s/ endpoint and check for signs of follow-on compromise, since ransomware operators are known to exploit this flaw. Where possible, restrict direct internet exposure of Confluence until patching is complete.
| Atlassian Confluence Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.
- Affected
- Atlassian Confluence Server
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- atlassian
- Products
- confluence data center, confluence server
- Weakness
- CWE-425
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N