Stored XSS and Privilege Escalation in Confluence Data Center and Server by Atlassian
CVE-2026-21580

8.6HIGH

Key Information:

Vendor

Atlassian

Vendor
CVE Published:
18 August 2026

What is CVE-2026-21580?

A vulnerability in Confluence Data Center and Server allows unauthenticated attackers to execute arbitrary HTML or JavaScript code in a victim's browser. This flaw can also enable actions to be performed as a higher-privileged user and allows unauthorized access to the system due to overlooked security best practices. Users are advised to upgrade to specified fixed versions or the latest release to mitigate this vulnerability.

Affected Version(s)

Confluence Data Center 10.2.0 to 10.2.11

Confluence Data Center 10.1.0 to 10.1.2

Confluence Data Center 10.0.2 to 10.0.3

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.