CVE-2026-21580
Awaiting Analysis Awaiting Analysis - Queue

Stored XSS and Privilege Escalation in Confluence Data Center and Server

Vulnerability report for CVE-2026-21580, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-26

Assigner: Atlassian

Description

This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability, with a CVSS Score of 8.6, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser, perform actions as a higher-privileged user, and to get into the system utilizing loopholes exposed from security best-practices being overlooked. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.21 Confluence Data Center and Server 10.2: Upgrade to a release greater than or equal to 10.2.13 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center and Server from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Bug Bounty program.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-26
Generated
2026-09-08
AI Q&A
2026-08-19
EPSS Evaluated
2026-09-06
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
atlassian confluence_data_center_and_server From 9.2.21 (inc)
atlassian confluence_data_center_and_server From 10.2.13 (inc)
atlassian confluence_data_center_and_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Critical severity vulnerability affecting multiple versions of Confluence Data Center and Server. It combines Stored Cross-Site Scripting (XSS), Privilege Escalation, and Security Misconfiguration issues. An unauthenticated attacker can inject malicious HTML or JavaScript code that executes in a victim's browser, escalate their privileges to higher levels, and gain unauthorized system access by exploiting security best-practice gaps.

Detection Guidance

This vulnerability requires checking Confluence version against affected releases. Use commands like 'curl -s https://your-confluence-instance.com/status | grep version' or check the admin panel for version info. Compare against versions 7.1.1 to 10.2.0.

Impact Analysis

An attacker could steal sensitive data, perform actions as an admin user, or take full control of your Confluence instance. This could lead to data breaches, unauthorized modifications, or complete system compromise. The impact includes potential loss of confidentiality, integrity, and availability of your Confluence environment.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR (data breaches), HIPAA (unauthorized access to protected health information), and other regulations. It may result in legal penalties, loss of certification, and reputational damage due to compromised sensitive data.

Mitigation Strategies

Upgrade Confluence Data Center and Server to a fixed version. For version 9.2, upgrade to 9.2.21 or later. For version 10.2, upgrade to 10.2.13 or later. If unable to upgrade, apply the latest supported fixed version immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21580. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart