CVE-2026-21586
largeImproper Authorization in Atlassian Confluence Data Center Could Expose Data, Enable RCE
Atlassian Confluence Data Center contains a high-severity improper authorization (broken access control) flaw introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0. A low-privileged authenticated attacker triggers it by accessing resources or functionality outside their authorized scope, which the product fails to restrict. Successful abuse grants unintended access that can expose sensitive information or restricted features and, in some cases, may allow arbitrary code execution. The affected population is self-hosted Confluence Data Center deployments on the listed versions that have not yet applied the 9.2.24 or 10.2.17 fixes. The flaw was found through Atlassian's penetration testing program; no public proof of concept or in-the-wild exploitation is known, and the CVE is not in CISA's KEV catalog.
What to do: Upgrade Confluence Data Center immediately: instances on the 9.2 branch to 9.2.24 or later, and instances on 9.3.x–10.2.x (or any older affected line) to 10.2.17 or the latest release. Until patched, restrict Confluence to trusted networks or VPN, minimize low-privilege account grants, and audit logs for authenticated users accessing spaces, pages, or administrative functions outside their expected permissions.
| Atlassian Confluence Data Center | 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, and 9.2.0 through versions before 9.2.24 (upgrade to 9.2.24 or later on the 9.2 branch) |
| Atlassian Confluence Data Center | 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 through versions before 10.2.17 (upgrade to 10.2.17 or later, or the latest release) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.24 Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.17 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Penetration Testing program.
- Weakness
- CWE-285
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.