PT-2026-92137 · Atlassian · Confluence

CVE-2026-21588

·

Published

2026-09-15

·

Updated

2026-09-16

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Confluence Data Center version 8.9.0 Confluence Data Center version 9.0.1 Confluence Data Center version 9.1.0 Confluence Data Center version 9.2.0 Confluence Data Center version 9.3.1 Confluence Data Center version 9.4.0 Confluence Data Center version 9.5.1 Confluence Data Center version 10.0.2 Confluence Data Center version 10.1.0 Confluence Data Center version 10.2.0
Description A Denial of Service (DoS) issue allows an authenticated attacker to disrupt the services of a connected host, making resources unavailable to intended users either temporarily or indefinitely.
Recommendations For version 9.2.0, upgrade to a release greater than or equal to 9.2.24. For version 10.2.0, upgrade to a release greater than or equal to 10.2.17. For versions 8.9.0, 9.0.1, 9.1.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, and 10.1.0, upgrade to the latest version.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-21588

Affected Products

Confluence