Vulnerability record · CVE-2021-26085 · published 3 August 2021
CVE-2021-26085: Atlassian Confluence Server pre-auth arbitrary file read via /s/ endpoint
Atlassian · Confluence Data Center
Confluence Server and Data Center expose a pre-authorization arbitrary file read through the /s/ endpoint, letting unauthenticated remote attackers view restricted resources. Affected versions are before 7.4.10 and 7.5.0 through 7.12.3. Because no credentials or user interaction are needed, any internet-facing instance is directly exposed.
Description
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has near-maximum EPSS, public exploits and requires no authentication, despite a medium CVSS base score.
What it is
Confluence Server and Data Center expose a pre-authorization arbitrary file read through the /s/ endpoint, letting unauthenticated remote attackers view restricted resources. Affected versions are before 7.4.10 and 7.5.0 through 7.12.3. Because no credentials or user interaction are needed, any internet-facing instance is directly exposed.
Impact
An attacker can read files and restricted resources on the server without authenticating, exposing configuration data, secrets and other sensitive content. The CVSS confidentiality impact is rated low, but the flaw has been used in ransomware campaigns, so downstream compromise is a real risk.
Attack surface
Reached over the network via the /s/ endpoint (CVSS AV:N, PR:N, UI:N); no authentication or user interaction is required. Any Confluence Server or Data Center instance on an affected version that is reachable by an attacker is in scope.
Exploitation
CISA added it to KEV on 2022-03-28 with a 2022-04-18 remediation due date and flags known ransomware campaign use; EPSS is 0.99937 (99.971st percentile) and public exploit references exist. Treat active exploitation as established.
What to do
- Upgrade Confluence Server/Data Center to 7.4.10 or later, or 7.12.3 or later, per the vendor advisory CONFSERVER-67893.
- If immediate patching is not possible, restrict network access to the /s/ endpoint and to Confluence generally using a reverse proxy or firewall allowlist.
- Remove or block direct internet exposure of Confluence instances until they are confirmed patched.
- Rotate credentials and secrets that may have been stored in files readable through this flaw, and review logs for prior access.
- Monitor the vendor advisory and CISA KEV entry for any updated guidance.
Detection
- Search web/proxy logs for requests to the /s/ endpoint, especially unusual paths or traversal sequences, from unauthenticated clients.
- Alert on access to the /s/ endpoint from IPs outside expected user ranges or with anomalous user agents.
- Correlate Confluence access logs with post-exploitation activity such as new admin accounts, plugin changes or outbound connections.
- Hunt for known exploit payload patterns against Confluence /s/ paths in IDS/IPS and WAF telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-26085 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/164401/Atlassian-Confluence-Server-7.5.1-Arbitrary-File-Read.html | ExploitThird Party AdvisoryVDB Entry |
| https://jira.atlassian.com/browse/CONFSERVER-67893 | Issue TrackingVendor Advisory |
| http://packetstormsecurity.com/files/164401/Atlassian-Confluence-Server-7.5.1-Arbitrary-File-Read.html | ExploitThird Party AdvisoryVDB Entry |
| https://jira.atlassian.com/browse/CONFSERVER-67893 | Issue TrackingVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26085 | US Government Resource |
Track CVE-2021-26085 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-26085), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.