Executive brief
Atlassian Confluence Data Center, a popular team collaboration and document management platform, is affected by a high-severity security flaw. This vulnerability allows an unauthorized person to access sensitive internal information without needing a username or password. Such an exploit could lead to the exposure of proprietary business data or internal documentation, potentially impacting corporate confidentiality and compliance.
Technical details
An information disclosure vulnerability exists in Atlassian Confluence Data Center across multiple version branches, including 7.x, 8.x, 9.x, and 10.x. The flaw allows a remote, unauthenticated attacker to view sensitive information due to improper access controls or data handling. According to the CVSS:4.0 vector, the attack is network-based, requires low technical complexity, and involves no user interaction, though it may require specific environmental conditions (Attack Terminology: P). Successful exploitation results in high confidentiality impact. Atlassian has released patches in versions 9.2.22 and 10.2.14 to address this issue.
Affected products
- Atlassian Confluence Data Center 7.17.0 to 10.2.13
Timeline
- 2026-07-09: other: Vulnerability record created in Atlassian Jira
- 2026-07-21: disclosed: Initial advisory publication
- 2026-07-21: patched: Fixed versions 9.2.22 and 10.2.14 released