Improper Authorization Vulnerability in Confluence Data Center by Atlassian
CVE-2026-21586
7.1HIGH
What is CVE-2026-21586?
An improper authorization vulnerability has been identified in certain versions of Atlassian's Confluence Data Center, which allows authenticated users to access sensitive resources unintentionally. This flaw can lead to unauthorized exposure of functionality and potentially enables attackers to retrieve sensitive data or execute arbitrary code. It is crucial for users of affected versions to upgrade to a supported fixed version, as per Atlassian’s recommendations, to mitigate these risks effectively.
Affected Version(s)
Confluence Data Center 10.2.1 to 10.2.15
Confluence Data Center 10.1.0 to 10.1.2
Confluence Data Center 10.0.2 to 10.0.3