ZeroHour

CVE-2026-21586

large

Improper Authorization in Atlassian Confluence Data Center Could Expose Data, Enable RCE

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

Atlassian Confluence Data Center contains a high-severity improper authorization (broken access control) flaw introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0. A low-privileged authenticated attacker triggers it by accessing resources or functionality outside their authorized scope, which the product fails to restrict. Successful abuse grants unintended access that can expose sensitive information or restricted features and, in some cases, may allow arbitrary code execution. The affected population is self-hosted Confluence Data Center deployments on the listed versions that have not yet applied the 9.2.24 or 10.2.17 fixes. The flaw was found through Atlassian's penetration testing program; no public proof of concept or in-the-wild exploitation is known, and the CVE is not in CISA's KEV catalog.

What to do: Upgrade Confluence Data Center immediately: instances on the 9.2 branch to 9.2.24 or later, and instances on 9.3.x–10.2.x (or any older affected line) to 10.2.17 or the latest release. Until patched, restrict Confluence to trusted networks or VPN, minimize low-privilege account grants, and audit logs for authenticated users accessing spaces, pages, or administrative functions outside their expected permissions.

Affected
Atlassian Confluence Data Center7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, and 9.2.0 through versions before 9.2.24 (upgrade to 9.2.24 or later on the 9.2 branch)
Atlassian Confluence Data Center9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 through versions before 10.2.17 (upgrade to 10.2.17 or later, or the latest release)
Estimated exposure
largeTens of thousands of self-hosted instances (≈20k–40k internet-reachable Confluence endpoints), plus a larger unseen population of internal/VPN-only deployments — Internet-wide scan services (Shodan/Censys) have historically shown tens of thousands of exposed Confluence endpoints, and Confluence Data Center is widely deployed in enterprise self-hosted environments behind firewalls, so the true count…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.24 Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.17 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Penetration Testing program.

Weakness
CWE-285
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.