CVE-2026-21580
Confluence Server Análisis y mitigación de vulnerabilidades

Vista general

CVE-2026-21580 is a Critical-severity Stored XSS, Privilege Escalation, and Security Misconfiguration vulnerability affecting Atlassian Confluence Data Center and Server. The vulnerability was introduced across multiple version branches starting from 7.1.1 and affects specific ranges up through 10.2.x; confirmed affected ranges include 7.19.27–7.19.30, 8.5.15–8.5.31, 8.9.6–8.9.8, 9.0.3, 9.1.0–9.1.1, 9.2.0–9.2.20, 9.3.1–9.3.2, 9.4.0–9.4.1, 9.5.1–9.5.4, 10.0.2–10.0.3, 10.1.0–10.1.2, and 10.2.0–10.2.11. It was disclosed on August 18, 2026, and reported through Atlassian's Bug Bounty program. The vulnerability carries a CVSS v4.0 base score of 9.3 (Critical) per GitHub Advisory and 8.6 (Critical) per Atlassian's own assessment (Atlassian Advisory, GitHub Advisory).

Técnicas

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) variant. An unauthenticated attacker can inject malicious HTML or JavaScript into Confluence content that is subsequently rendered in other users' browsers without proper sanitization or output encoding. The vulnerability is compounded by security misconfigurations that enable privilege escalation, allowing the attacker to perform actions as a higher-privileged user by leveraging the stored payload against authenticated sessions. No specific technical write-up or public PoC code has been identified at this time (GitHub Advisory, Atlassian Advisory).

Impacto

Successful exploitation allows an unauthenticated attacker to execute arbitrary HTML or JavaScript in victims' browsers, potentially hijacking authenticated sessions, stealing credentials or sensitive data, and performing unauthorized actions on behalf of higher-privileged users including administrators. The privilege escalation component means an attacker could gain administrative control over the Confluence instance, exposing all stored content, user data, and integrated systems. The CVSS v4.0 scoring reflects high impacts to confidentiality, integrity, and availability of the vulnerable system (GitHub Advisory, Atlassian Advisory).

Explotabilidad

As of the disclosure date, there is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment notes the vulnerability is automatable with total technical impact, but exploitation status is listed as "none" at this time. The EPSS score is approximately 0.355–0.395%, placing it in roughly the 32nd percentile for exploitation likelihood within 30 days. No threat actor attribution or CISA KEV catalog listing has been identified (GitHub Advisory).

Mitigación y soluciones alternativas

Atlassian recommends upgrading to the latest version of Confluence Data Center and Server. For organizations unable to upgrade to the latest release, the following minimum fixed versions are available: Confluence Data Center and Server 9.2 branch: upgrade to 9.2.21 or later; Confluence Data Center and Server 10.2 branch: upgrade to 10.2.13 or later. The recommended versions as of the bulletin date are 10.2.15 (LTS) for Data Center and 9.2.23 (LTS) for Data Center. No configuration-based workaround has been published; patching is the only remediation (Atlassian Advisory, GitHub Advisory).

Reacciones de la comunidad

The vulnerability received coverage from security news outlets and community aggregators shortly after disclosure, including posts on Mastodon's infosec community and coverage by SecurityOnline.info. CyCognito published a blog post characterizing it as an "emerging threat" focused on the privilege escalation via unauthenticated stored XSS angle. General community sentiment reflects concern given the unauthenticated attack vector and the breadth of affected Confluence versions, though the absence of a public PoC has tempered urgency somewhat (Atlassian Advisory).

Recursos adicionales


FuenteEste informe se generó utilizando IA

Relacionado Confluence Server Vulnerabilidades:

CVE ID

Severidad

Puntuación

Tecnologías

Nombre del componente

Exploit de CISA KEV

Tiene arreglo

Fecha de publicación

CVE-2026-21580CRITICAL9.3
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
NoNoAug 18, 2026
CVE-2024-21686HIGH8.7
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
NoJul 16, 2024
CVE-2025-22166HIGH8.3
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
NoOct 21, 2025
CVE-2024-21690HIGH8.2
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
NoAug 21, 2024
CVE-2024-21703MEDIUM6.4
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
NoNov 27, 2024

Evaluación gratuita de vulnerabilidades

Compare su postura de seguridad en la nube

Evalúe sus prácticas de seguridad en la nube en 9 dominios de seguridad para comparar su nivel de riesgo e identificar brechas en sus defensas.

Solicitar evaluación

Recursos adicionales de Wiz

Obtén una demostración personalizada

¿Listo para ver a Wiz en acción?

"La mejor experiencia de usuario que he visto en mi vida, proporciona una visibilidad completa de las cargas de trabajo en la nube."
David EstlickCISO
"Wiz proporciona un panel único para ver lo que ocurre en nuestros entornos en la nube."
Adam FletcherJefe de Seguridad
"Sabemos que si Wiz identifica algo como crítico, en realidad lo es."
Greg PoniatowskiJefe de Gestión de Amenazas y Vulnerabilidades