CVE-2026-21588
moderateAuthenticated Denial-of-Service in Atlassian Confluence Data Center
CVE-2026-21588 is a high-severity denial-of-service (DoS) vulnerability affecting multiple versions of Atlassian's self-hosted Confluence Data Center, introduced in versions 8.9.0 through 10.2.0 on the listed branches. An authenticated attacker with low privileges can trigger the flaw over the network with no user interaction, temporarily or indefinitely disrupting the availability of the Confluence host for legitimate users. The CVSS 4.0 score of 7.1 reflects high availability impact only; confidentiality and integrity are not compromised. The flaw was found through Atlassian's penetration testing program, is not in the CISA KEV catalog, and has no known public proof-of-concept or observed exploitation. All organizations running Confluence Data Center on the affected versions are exposed, with a reduced (but not eliminated) risk profile since valid credentials are required.
What to do: Upgrade Confluence Data Center 9.2.x to 9.2.24 or later and 10.2.x to 10.2.17 or later; if running an older affected branch (8.9, 9.0, 9.1, 9.3, 9.4, 9.5, 10.0, 10.1), upgrade to the latest release since no backported fixes are specified. In the interim, audit and restrict authenticated user accounts, apply rate limiting or WAF rules to detect abnormal request patterns, and monitor Confluence logs for repeated resource-exhaustion events tied to low-privileged users.
| Atlassian Confluence Data Center | 8.9.0, 9.0.1, 9.1.0, 9.2.0 (9.2.x < 9.2.24), 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, 10.2.0 (10.2.x < 10.2.17) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.24 Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.17 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Penetration Testing program.
- Weakness
- CWE-400
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.