CVE-2021-26085mediumunder attackransomwareCWE-425

CVE-2021-26085: medium-severity vulnerability in Atlassian Confluence Server

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 5.3epss 100%
from disclosure to weapon63 days
Published on NVDAug 3
1st PoC+63d
CISA KEV+237d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
4 public exploit(s)
Action required by CISAfederal deadline: 2022-04-18

Apply updates per vendor instructions.

In short

Atlassian Confluence Server has a vulnerability that allows attackers to read files they shouldn't have access to by exploiting the /s/ endpoint. This means sensitive information could be exposed without proper authentication.

Technical detail

A pre-authorization arbitrary file read vulnerability exists in the /s/ endpoint of Confluence Server versions before 7.4.10 and 7.5.0–7.12.2, allowing unauthenticated remote attackers to bypass access controls and retrieve restricted files. The vulnerability stems from insufficient authorization checks on file retrieval operations, potentially exposing sensitive configuration or user data.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.