ZeroHour

CVE-2021-26085

KEV ransomware PoC large

Unauthenticated Arbitrary File Read in Atlassian Confluence Server

CISA: Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

CVSS 3.1
5.3 medium
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2021-26085 is a pre-authorization arbitrary file read (CWE-425) in Atlassian Confluence Server, meaning an attacker needs no credentials to exploit it. It is triggered by sending crafted remote requests to Confluence's /s/ endpoint, which serves static resources, causing the server to expose restricted resources and files outside what an unauthenticated user should reach. Successful exploitation grants read access to arbitrary files on the Confluence host, which can expose configuration files, credentials, and other sensitive data. All unpatched Atlassian Confluence Server deployments are affected, particularly instances reachable from the internet. The flaw is listed in the CISA KEV catalog (added 2022-03-28) with known ransomware use, and its 99.9% EPSS probability of exploitation within 30 days indicates very widespread targeting, though no public PoC is cataloged.

What to do: Apply Atlassian's official updates for CVE-2021-26085 per the vendor's instructions as required by the CISA KEV listing, prioritizing internet-facing Confluence servers. Review access logs for suspicious requests to the /s/ endpoint and check for signs of follow-on compromise, since ransomware operators are known to exploit this flaw. Where possible, restrict direct internet exposure of Confluence until patching is complete.

Affected
Atlassian Confluence Server
Estimated exposure
largeon the order of tens of thousands of internet-exposed Confluence Server instances, plus many more internal enterprise deployments — Confluence Server is a widely deployed enterprise wiki with a large installed base, and public internet scans (Shodan/Censys) have historically surfaced tens of thousands of externally reachable Confluence instances, while many additional…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

CISA Known Exploited Vulnerability
Affected
Atlassian Confluence Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
atlassian
Products
confluence data center, confluence server
Weakness
CWE-425
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news