CVE-2021-26085

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
03/08/2021
Last modified:
24/10/2025

Description

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:* 7.4.10 (excluding)
cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:* 7.5.0 (including) 7.12.3 (excluding)
cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:* 7.4.10 (excluding)
cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:* 7.5.0 (including) 7.12.3 (excluding)