CVE-2026-21580
Confluence Server 脆弱性の分析と軽減

概要

CVE-2026-21580 is a Critical-severity Stored XSS, Privilege Escalation, and Security Misconfiguration vulnerability affecting Atlassian Confluence Data Center and Server. The vulnerability was introduced across multiple version branches starting from 7.1.1 and affects specific ranges up through 10.2.x; confirmed affected ranges include 7.19.27–7.19.30, 8.5.15–8.5.31, 8.9.6–8.9.8, 9.0.3, 9.1.0–9.1.1, 9.2.0–9.2.20, 9.3.1–9.3.2, 9.4.0–9.4.1, 9.5.1–9.5.4, 10.0.2–10.0.3, 10.1.0–10.1.2, and 10.2.0–10.2.11. It was disclosed on August 18, 2026, and reported through Atlassian's Bug Bounty program. The vulnerability carries a CVSS v4.0 base score of 9.3 (Critical) per GitHub Advisory and 8.6 (Critical) per Atlassian's own assessment (Atlassian Advisory, GitHub Advisory).

技術的な詳細

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) variant. An unauthenticated attacker can inject malicious HTML or JavaScript into Confluence content that is subsequently rendered in other users' browsers without proper sanitization or output encoding. The vulnerability is compounded by security misconfigurations that enable privilege escalation, allowing the attacker to perform actions as a higher-privileged user by leveraging the stored payload against authenticated sessions. No specific technical write-up or public PoC code has been identified at this time (GitHub Advisory, Atlassian Advisory).

影響

Successful exploitation allows an unauthenticated attacker to execute arbitrary HTML or JavaScript in victims' browsers, potentially hijacking authenticated sessions, stealing credentials or sensitive data, and performing unauthorized actions on behalf of higher-privileged users including administrators. The privilege escalation component means an attacker could gain administrative control over the Confluence instance, exposing all stored content, user data, and integrated systems. The CVSS v4.0 scoring reflects high impacts to confidentiality, integrity, and availability of the vulnerable system (GitHub Advisory, Atlassian Advisory).

エクスプロイト可能性

As of the disclosure date, there is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment notes the vulnerability is automatable with total technical impact, but exploitation status is listed as "none" at this time. The EPSS score is approximately 0.355–0.395%, placing it in roughly the 32nd percentile for exploitation likelihood within 30 days. No threat actor attribution or CISA KEV catalog listing has been identified (GitHub Advisory).

軽減策と回避策

Atlassian recommends upgrading to the latest version of Confluence Data Center and Server. For organizations unable to upgrade to the latest release, the following minimum fixed versions are available: Confluence Data Center and Server 9.2 branch: upgrade to 9.2.21 or later; Confluence Data Center and Server 10.2 branch: upgrade to 10.2.13 or later. The recommended versions as of the bulletin date are 10.2.15 (LTS) for Data Center and 9.2.23 (LTS) for Data Center. No configuration-based workaround has been published; patching is the only remediation (Atlassian Advisory, GitHub Advisory).

コミュニティの反応

The vulnerability received coverage from security news outlets and community aggregators shortly after disclosure, including posts on Mastodon's infosec community and coverage by SecurityOnline.info. CyCognito published a blog post characterizing it as an "emerging threat" focused on the privilege escalation via unauthenticated stored XSS angle. General community sentiment reflects concern given the unauthenticated attack vector and the breadth of affected Confluence versions, though the absence of a public PoC has tempered urgency somewhat (Atlassian Advisory).

関連情報


ソースこのレポートは AI を使用して生成されました

関連 Confluence Server 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-21580CRITICAL9.3
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
いいえいいえAug 18, 2026
CVE-2024-21686HIGH8.7
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
いいえはいJul 16, 2024
CVE-2025-22166HIGH8.3
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
いいえはいOct 21, 2025
CVE-2024-21690HIGH8.2
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
いいえはいAug 21, 2024
CVE-2024-21703MEDIUM6.4
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
いいえはいNov 27, 2024

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者