Junglewise Threat Intelligence

CVE-2026-21588: Atlassian Confluence Data Center DoS in authenticated request handling

CVE-2026-21588 · Severity: info · CVSS 7.1 · Published 2026-09-15

Executive brief

Confluence Data Center is a widely deployed enterprise document collaboration platform used by organizations to manage documentation and team knowledge. An authenticated user can exploit a denial-of-service vulnerability to temporarily or permanently disrupt the availability of a Confluence instance, preventing legitimate users from accessing documents and collaboration features. Remediation requires upgrading to patched versions 9.2.24, 10.2.17, or later.

Technical details

This is a denial-of-service vulnerability affecting Confluence Data Center versions 8.9.0 through 10.2.x. The vulnerability requires prior authentication but allows an attacker to cause resource exhaustion or service disruption via a crafted request. The attack vector is network-based (AV:N) with low complexity (AC:L), and requires user login credentials (PR:L). An authenticated attacker can indefinitely disrupt services of the affected host. The vulnerability has been patched in Confluence Data Center 9.2.24 and 10.2.17 or later. CVSS v4.0 score is 7.1 (High), with the primary impact being availability (VA:H).

Affected products

  • Atlassian Confluence Data Center 8.9.0 through 10.2.16 (fixed in 9.2.24, 10.2.17 and later)

Timeline

  • 2026-09-15: disclosed: Published in Atlassian Security Bulletin
  • 2026-09-15: patched: Fixed versions 9.2.24 and 10.2.17 released

References

Related threats