MEDIUM
CVE-2021-26085
CVSS
5.3
KEV
Description
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.
Summary dbcve.org
Atlassian Confluence Server contains a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. Attackers can exploit this vulnerability without authentication to read arbitrary files on the server, leading to information disclosure.
Mitigation
Upgrade Confluence Server to version 7.4.10, 7.12.3, or later to remediate this vulnerability.
Weakness (CWE)
CWE-425
EPSS Score
99.94%
Probability of exploitation in next 30 days
100th percentile
References
http://packetstormsecurity.com/files/164401/Atlassian-Confluence-Server-7.5.1-Arbitrary-File-Read.html
Exploit, Third Party Advisory, VDB Entry
https://jira.atlassian.com/browse/CONFSERVER-67893
Issue Tracking, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26085
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.