
PEACH
Un framework di isolamento del tenant
CVE-2026-21580 is a Critical-severity Stored XSS, Privilege Escalation, and Security Misconfiguration vulnerability affecting Atlassian Confluence Data Center and Server. The vulnerability was introduced across multiple version branches starting from 7.1.1 and affects specific ranges up through 10.2.x; confirmed affected ranges include 7.19.27–7.19.30, 8.5.15–8.5.31, 8.9.6–8.9.8, 9.0.3, 9.1.0–9.1.1, 9.2.0–9.2.20, 9.3.1–9.3.2, 9.4.0–9.4.1, 9.5.1–9.5.4, 10.0.2–10.0.3, 10.1.0–10.1.2, and 10.2.0–10.2.11. It was disclosed on August 18, 2026, and reported through Atlassian's Bug Bounty program. The vulnerability carries a CVSS v4.0 base score of 9.3 (Critical) per GitHub Advisory and 8.6 (Critical) per Atlassian's own assessment (Atlassian Advisory, GitHub Advisory).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) variant. An unauthenticated attacker can inject malicious HTML or JavaScript into Confluence content that is subsequently rendered in other users' browsers without proper sanitization or output encoding. The vulnerability is compounded by security misconfigurations that enable privilege escalation, allowing the attacker to perform actions as a higher-privileged user by leveraging the stored payload against authenticated sessions. No specific technical write-up or public PoC code has been identified at this time (GitHub Advisory, Atlassian Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary HTML or JavaScript in victims' browsers, potentially hijacking authenticated sessions, stealing credentials or sensitive data, and performing unauthorized actions on behalf of higher-privileged users including administrators. The privilege escalation component means an attacker could gain administrative control over the Confluence instance, exposing all stored content, user data, and integrated systems. The CVSS v4.0 scoring reflects high impacts to confidentiality, integrity, and availability of the vulnerable system (GitHub Advisory, Atlassian Advisory).
As of the disclosure date, there is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment notes the vulnerability is automatable with total technical impact, but exploitation status is listed as "none" at this time. The EPSS score is approximately 0.355–0.395%, placing it in roughly the 32nd percentile for exploitation likelihood within 30 days. No threat actor attribution or CISA KEV catalog listing has been identified (GitHub Advisory).
Atlassian recommends upgrading to the latest version of Confluence Data Center and Server. For organizations unable to upgrade to the latest release, the following minimum fixed versions are available: Confluence Data Center and Server 9.2 branch: upgrade to 9.2.21 or later; Confluence Data Center and Server 10.2 branch: upgrade to 10.2.13 or later. The recommended versions as of the bulletin date are 10.2.15 (LTS) for Data Center and 9.2.23 (LTS) for Data Center. No configuration-based workaround has been published; patching is the only remediation (Atlassian Advisory, GitHub Advisory).
The vulnerability received coverage from security news outlets and community aggregators shortly after disclosure, including posts on Mastodon's infosec community and coverage by SecurityOnline.info. CyCognito published a blog post characterizing it as an "emerging threat" focused on the privilege escalation via unauthenticated stored XSS angle. General community sentiment reflects concern given the unauthenticated attack vector and the breadth of affected Confluence versions, though the absence of a public PoC has tempered urgency somewhat (Atlassian Advisory).
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."