PT-2026-78242 · Atlassian · Confluence
CVE-2026-21580
·
Published
2026-08-18
·
Updated
2026-08-21
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Confluence Data Center and Server versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0
Description
A stored Cross-Site Scripting (XSS), privilege escalation, and security misconfiguration issue allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code in a victim's browser. This can enable the attacker to perform actions as a higher-privileged user and gain system access by exploiting loopholes resulting from overlooked security best practices.
Recommendations
Upgrade Confluence Data Center and Server version 9.2 to a release greater than or equal to 9.2.21.
Upgrade Confluence Data Center and Server version 10.2 to a release greater than or equal to 10.2.13.
Fix
LPE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Confluence