Junglewise Threat Intelligence

CVE-2026-21586: Atlassian Confluence Data Center improper authorization

CVE-2026-21586 · Severity: info · CVSS 7.1 · Published 2026-09-15

Executive brief

Confluence Data Center is Atlassian's enterprise document collaboration platform used by organizations to centralize team knowledge and documentation. An authentication bypass vulnerability allows authenticated users to access resources or functionality they should not have permission to view, potentially exposing sensitive documents or enabling unauthorized operations that could compromise data integrity or confidentiality.

Technical details

This is an improper authorization vulnerability (CWE-269) affecting Confluence Data Center across multiple versions starting from 7.4.0 through 10.2.0. An authenticated attacker can exploit insufficient access control checks to gain unintended privileges and access restricted resources or functionality. The vulnerability requires valid credentials to exploit (authenticated attack vector, PR:L) and is reachable over the network without user interaction required. Successful exploitation can lead to exposure of sensitive data. Patches are available: upgrade to Confluence Data Center 9.2.24 or later (9.2.x branch) or 10.2.17 or later (10.2.x branch).

Affected products

  • Atlassian Confluence Data Center 7.4.0, 7.13.0, 7.19.0, 8.5.0, 8.9.0-8.9.8, 9.0.1-9.0.2, 9.1.0-9.1.1, 9.2.0-9.2.23, 9.3.1-9.3.2, 9.4.0-9.4.1, 9.5.1-9.5.4, 10.0.2-10.0.3, 10.1.0-10.1.2, 10.2.0-10.2.16

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed versions: 9.2.24, 10.2.17

References

Related threats