CVE-2026-21580
Confluence Server Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-21580 is a Critical-severity Stored XSS, Privilege Escalation, and Security Misconfiguration vulnerability affecting Atlassian Confluence Data Center and Server. The vulnerability was introduced across multiple version branches starting from 7.1.1 and affects specific ranges up through 10.2.x; confirmed affected ranges include 7.19.27–7.19.30, 8.5.15–8.5.31, 8.9.6–8.9.8, 9.0.3, 9.1.0–9.1.1, 9.2.0–9.2.20, 9.3.1–9.3.2, 9.4.0–9.4.1, 9.5.1–9.5.4, 10.0.2–10.0.3, 10.1.0–10.1.2, and 10.2.0–10.2.11. It was disclosed on August 18, 2026, and reported through Atlassian's Bug Bounty program. The vulnerability carries a CVSS v4.0 base score of 9.3 (Critical) per GitHub Advisory and 8.6 (Critical) per Atlassian's own assessment (Atlassian Advisory, GitHub Advisory).

Detalhes técnicos

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) variant. An unauthenticated attacker can inject malicious HTML or JavaScript into Confluence content that is subsequently rendered in other users' browsers without proper sanitization or output encoding. The vulnerability is compounded by security misconfigurations that enable privilege escalation, allowing the attacker to perform actions as a higher-privileged user by leveraging the stored payload against authenticated sessions. No specific technical write-up or public PoC code has been identified at this time (GitHub Advisory, Atlassian Advisory).

Impacto

Successful exploitation allows an unauthenticated attacker to execute arbitrary HTML or JavaScript in victims' browsers, potentially hijacking authenticated sessions, stealing credentials or sensitive data, and performing unauthorized actions on behalf of higher-privileged users including administrators. The privilege escalation component means an attacker could gain administrative control over the Confluence instance, exposing all stored content, user data, and integrated systems. The CVSS v4.0 scoring reflects high impacts to confidentiality, integrity, and availability of the vulnerable system (GitHub Advisory, Atlassian Advisory).

Exploração

As of the disclosure date, there is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment notes the vulnerability is automatable with total technical impact, but exploitation status is listed as "none" at this time. The EPSS score is approximately 0.355–0.395%, placing it in roughly the 32nd percentile for exploitation likelihood within 30 days. No threat actor attribution or CISA KEV catalog listing has been identified (GitHub Advisory).

Mitigação e soluções alternativas

Atlassian recommends upgrading to the latest version of Confluence Data Center and Server. For organizations unable to upgrade to the latest release, the following minimum fixed versions are available: Confluence Data Center and Server 9.2 branch: upgrade to 9.2.21 or later; Confluence Data Center and Server 10.2 branch: upgrade to 10.2.13 or later. The recommended versions as of the bulletin date are 10.2.15 (LTS) for Data Center and 9.2.23 (LTS) for Data Center. No configuration-based workaround has been published; patching is the only remediation (Atlassian Advisory, GitHub Advisory).

Reações da comunidade

The vulnerability received coverage from security news outlets and community aggregators shortly after disclosure, including posts on Mastodon's infosec community and coverage by SecurityOnline.info. CyCognito published a blog post characterizing it as an "emerging threat" focused on the privilege escalation via unauthenticated stored XSS angle. General community sentiment reflects concern given the unauthenticated attack vector and the breadth of affected Confluence versions, though the absence of a public PoC has tempered urgency somewhat (Atlassian Advisory).

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado Confluence Server Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-21580CRITICAL9.3
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
NãoNãoAug 18, 2026
CVE-2024-21686HIGH8.7
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
NãoSimJul 16, 2024
CVE-2025-22166HIGH8.3
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
NãoSimOct 21, 2025
CVE-2024-21690HIGH8.2
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
NãoSimAug 21, 2024
CVE-2024-21703MEDIUM6.4
  • Confluence Server logoConfluence Server
  • cpe:2.3:a:atlassian:confluence_server
NãoSimNov 27, 2024

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades