Junglewise Threat Intelligence

CVE-2026-21577: Atlassian Confluence Data Center denial of service

CVE-2026-21577 · Severity: info · CVSS 7.1 · Published 2026-07-21

Executive brief

Atlassian Confluence Data Center, a popular team collaboration and documentation platform, is affected by a security flaw that could allow a user to crash the service. An authenticated attacker can exploit this vulnerability to make the platform unavailable to other employees, disrupting business operations and internal communications. Atlassian has released updates to resolve this issue and recommends upgrading to the latest version.

Technical details

A Denial of Service (DoS) vulnerability exists in Atlassian Confluence Data Center across multiple versions in the 9.x and 10.x branches. The flaw allows a remote, authenticated attacker with low privileges to exhaust system resources or otherwise disrupt the host services, leading to a temporary or indefinite loss of availability for the application. The vulnerability was identified through Atlassian's internal penetration testing program. Fixes have been backported to Long Term Support (LTS) releases, specifically versions 9.2.17 and 10.2.7.

Affected products

  • Atlassian Confluence Data Center 9.0.1 to 9.5.4, 10.0.2 to 10.2.6

Timeline

  • 2026-07-08: other: Internal issue created in Atlassian Jira
  • 2026-07-21: advisory: Security bulletin published by Atlassian
  • 2026-07-21: disclosed: CVE-2026-21577 published to NVD

References

Related threats