CVE-2026-21580
Confluence Server Schwachstellenanalyse und -minderung

Überblick

CVE-2026-21580 is a Critical-severity Stored XSS, Privilege Escalation, and Security Misconfiguration vulnerability affecting Atlassian Confluence Data Center and Server. The vulnerability was introduced across multiple version branches starting from 7.1.1 and affects specific ranges up through 10.2.x; confirmed affected ranges include 7.19.27–7.19.30, 8.5.15–8.5.31, 8.9.6–8.9.8, 9.0.3, 9.1.0–9.1.1, 9.2.0–9.2.20, 9.3.1–9.3.2, 9.4.0–9.4.1, 9.5.1–9.5.4, 10.0.2–10.0.3, 10.1.0–10.1.2, and 10.2.0–10.2.11. It was disclosed on August 18, 2026, and reported through Atlassian's Bug Bounty program. The vulnerability carries a CVSS v4.0 base score of 9.3 (Critical) per GitHub Advisory and 8.6 (Critical) per Atlassian's own assessment (Atlassian Advisory, GitHub Advisory).

Technische Details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) variant. An unauthenticated attacker can inject malicious HTML or JavaScript into Confluence content that is subsequently rendered in other users' browsers without proper sanitization or output encoding. The vulnerability is compounded by security misconfigurations that enable privilege escalation, allowing the attacker to perform actions as a higher-privileged user by leveraging the stored payload against authenticated sessions. No specific technical write-up or public PoC code has been identified at this time (GitHub Advisory, Atlassian Advisory).

Aufprall

Successful exploitation allows an unauthenticated attacker to execute arbitrary HTML or JavaScript in victims' browsers, potentially hijacking authenticated sessions, stealing credentials or sensitive data, and performing unauthorized actions on behalf of higher-privileged users including administrators. The privilege escalation component means an attacker could gain administrative control over the Confluence instance, exposing all stored content, user data, and integrated systems. The CVSS v4.0 scoring reflects high impacts to confidentiality, integrity, and availability of the vulnerable system (GitHub Advisory, Atlassian Advisory).

Ausnutzbarkeit

As of the disclosure date, there is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment notes the vulnerability is automatable with total technical impact, but exploitation status is listed as "none" at this time. The EPSS score is approximately 0.355–0.395%, placing it in roughly the 32nd percentile for exploitation likelihood within 30 days. No threat actor attribution or CISA KEV catalog listing has been identified (GitHub Advisory).

Risikominderung und Problemumgehungen

Atlassian recommends upgrading to the latest version of Confluence Data Center and Server. For organizations unable to upgrade to the latest release, the following minimum fixed versions are available: Confluence Data Center and Server 9.2 branch: upgrade to 9.2.21 or later; Confluence Data Center and Server 10.2 branch: upgrade to 10.2.13 or later. The recommended versions as of the bulletin date are 10.2.15 (LTS) for Data Center and 9.2.23 (LTS) for Data Center. No configuration-based workaround has been published; patching is the only remediation (Atlassian Advisory, GitHub Advisory).

Reaktionen der Community

The vulnerability received coverage from security news outlets and community aggregators shortly after disclosure, including posts on Mastodon's infosec community and coverage by SecurityOnline.info. CyCognito published a blog post characterizing it as an "emerging threat" focused on the privilege escalation via unauthenticated stored XSS angle. General community sentiment reflects concern given the unauthenticated attack vector and the breadth of affected Confluence versions, though the absence of a public PoC has tempered urgency somewhat (Atlassian Advisory).

Zusätzliche Ressourcen


QuelleDieser Bericht wurde mithilfe von KI erstellt

Verwandt Confluence Server Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-21580CRITICAL9.3
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
NeinNeinAug 18, 2026
CVE-2024-21686HIGH8.7
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
NeinJaJul 16, 2024
CVE-2025-22166HIGH8.3
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
NeinJaOct 21, 2025
CVE-2024-21690HIGH8.2
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
NeinJaAug 21, 2024
CVE-2024-21703MEDIUM6.4
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
NeinJaNov 27, 2024

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement