← Vulnerability feed

Vulnerability record · CVE-2021-26085 · published 3 August 2021

CVE-2021-26085: Atlassian Confluence Server pre-auth arbitrary file read via /s/ endpoint

Atlassian · Confluence Data Center

Confluence Server and Data Center expose a pre-authorization arbitrary file read through the /s/ endpoint, letting unauthenticated remote attackers view restricted resources. Affected versions are before 7.4.10 and 7.5.0 through 7.12.3. Because no credentials or user interaction are needed, any internet-facing instance is directly exposed.

5.3 CVSS 3.1 Medium CISA KEV since 28 Mar 2022 Known ransomware use EPSS 100% · top 0.1% CWE-425 · CWE-425
5.3CVSS 3.1 base score, v2 5.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, has near-maximum EPSS, public exploits and requires no authentication, despite a medium CVSS base score.

What it is

Confluence Server and Data Center expose a pre-authorization arbitrary file read through the /s/ endpoint, letting unauthenticated remote attackers view restricted resources. Affected versions are before 7.4.10 and 7.5.0 through 7.12.3. Because no credentials or user interaction are needed, any internet-facing instance is directly exposed.

Impact

An attacker can read files and restricted resources on the server without authenticating, exposing configuration data, secrets and other sensitive content. The CVSS confidentiality impact is rated low, but the flaw has been used in ransomware campaigns, so downstream compromise is a real risk.

Attack surface

Reached over the network via the /s/ endpoint (CVSS AV:N, PR:N, UI:N); no authentication or user interaction is required. Any Confluence Server or Data Center instance on an affected version that is reachable by an attacker is in scope.

Exploitation

CISA added it to KEV on 2022-03-28 with a 2022-04-18 remediation due date and flags known ransomware campaign use; EPSS is 0.99937 (99.971st percentile) and public exploit references exist. Treat active exploitation as established.

What to do

  • Upgrade Confluence Server/Data Center to 7.4.10 or later, or 7.12.3 or later, per the vendor advisory CONFSERVER-67893.
  • If immediate patching is not possible, restrict network access to the /s/ endpoint and to Confluence generally using a reverse proxy or firewall allowlist.
  • Remove or block direct internet exposure of Confluence instances until they are confirmed patched.
  • Rotate credentials and secrets that may have been stored in files readable through this flaw, and review logs for prior access.
  • Monitor the vendor advisory and CISA KEV entry for any updated guidance.

Detection

  • Search web/proxy logs for requests to the /s/ endpoint, especially unusual paths or traversal sequences, from unauthenticated clients.
  • Alert on access to the /s/ endpoint from IPs outside expected user ranges or with anomalous user agents.
  • Correlate Confluence access logs with post-exploitation activity such as new admin accounts, plugin changes or outbound connections.
  • Hunt for known exploit payload patterns against Confluence /s/ paths in IDS/IPS and WAF telemetry.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-26085 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-26085 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-22527Atlassian Confluence Data Center and Server template injection RCEOlder versions of Confluence Data Center and Server contain a template injection flaw (CWE-74) that lets an unauthenticated attacker execute code on …KEVEPSS 100%analysed9.8CVE-2023-22518Atlassian Confluence improper authorization allows admin account creationConfluence Data Center and Server contain an improper authorization flaw that lets an unauthenticated attacker reset Confluence and create an instanc…KEVEPSS 100%analysed9.8CVE-2023-22515Atlassian Confluence Data Center and Server broken access control allows admin account creationConfluence Data Center and Server contain a broken access control flaw that lets an unauthenticated external attacker create unauthorized administrat…KEVEPSS 99%analysed9.8CVE-2022-26134Atlassian Confluence Server and Data Center OGNL injection RCEConfluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker execute arbitrary code on …KEVEPSS 100%analysed9.8CVE-2021-26084Atlassian Confluence Server and Data Center OGNL injection RCEConfluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker run arbitrary code on the …KEVEPSS 100%analysed9.8CVE-2019-3396Atlassian Confluence Widget Connector path traversal and RCE via SSTIThe Widget Connector macro in Atlassian Confluence Server and Data Center fails to safely handle template input, allowing server-side template inject…KEVEPSS 100%analysed8.8CVE-2019-3398Atlassian Confluence Server path traversal in downloadallattachmentsConfluence Server and Data Center contain a path traversal flaw in the downloadallattachments resource. An attacker with permission to add attachment…KEVEPSS 97%analysed9.8CVE-2022-26136Atlassian bamboo improper authentication vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps…EPSS 5.4%

Source: NIST National Vulnerability Database (record CVE-2021-26085), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.