CVE-2021-26085
Atlassian Confluence Server, Atlassian Confluence Data Center
Published 3 Aug 2021 · updated 17 Jun 2026 · Analyzed
5.3 Medium · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 28 Mar 2022, with a remediation deadline of 18 Apr 2022 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply updates per vendor instructions.
Description
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.
References
- packetstormsecurity.com/files/164401/Atlassian-Confluence-Server-7.5.1-Arbitrary-File-Read.html · Exploit, Third Party Advisory, VDB Entry
- jira.atlassian.com/browse/CONFSERVER-67893 · Issue Tracking, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26085 · US Government Resource