PT-2026-92137 · Atlassian · Confluence
CVE-2026-21588
·
Published
2026-09-15
·
Updated
2026-09-16
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Confluence Data Center version 8.9.0
Confluence Data Center version 9.0.1
Confluence Data Center version 9.1.0
Confluence Data Center version 9.2.0
Confluence Data Center version 9.3.1
Confluence Data Center version 9.4.0
Confluence Data Center version 9.5.1
Confluence Data Center version 10.0.2
Confluence Data Center version 10.1.0
Confluence Data Center version 10.2.0
Description
A Denial of Service (DoS) issue allows an authenticated attacker to disrupt the services of a connected host, making resources unavailable to intended users either temporarily or indefinitely.
Recommendations
For version 9.2.0, upgrade to a release greater than or equal to 9.2.24.
For version 10.2.0, upgrade to a release greater than or equal to 10.2.17.
For versions 8.9.0, 9.0.1, 9.1.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, and 10.1.0, upgrade to the latest version.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Confluence