CVE-2026-21577 (GCVE-0-2026-21577)
Vulnerability from cvelistv5
Published
2026-07-21 17:00
Modified
2026-07-22 18:48
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- DoS (Denial of Service)
Summary
This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center.
This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network.
Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.17
Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.7
See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).
This vulnerability was reported via our Penetration Testing program.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Atlassian | Confluence Data Center |
Version: 10.2.0 to 10.2.6 Version: 10.1.0 to 10.1.2 Version: 10.0.2 to 10.0.3 Version: 9.5.1 to 9.5.4 Version: 9.4.0 to 9.4.1 Version: 9.3.1 to 9.3.2 Version: 9.2.0 to 9.2.15 Version: 9.1.0 to 9.1.1 Version: 9.0.1 to 9.0.3 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-21577",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-22T18:32:38.139315Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400 Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-22T18:48:52.568Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Confluence Data Center",
"vendor": "Atlassian",
"versions": [
{
"status": "affected",
"version": "10.2.0 to 10.2.6"
},
{
"status": "affected",
"version": "10.1.0 to 10.1.2"
},
{
"status": "affected",
"version": "10.0.2 to 10.0.3"
},
{
"status": "affected",
"version": "9.5.1 to 9.5.4"
},
{
"status": "affected",
"version": "9.4.0 to 9.4.1"
},
{
"status": "affected",
"version": "9.3.1 to 9.3.2"
},
{
"status": "affected",
"version": "9.2.0 to 9.2.15"
},
{
"status": "affected",
"version": "9.1.0 to 9.1.1"
},
{
"status": "affected",
"version": "9.0.1 to 9.0.3"
},
{
"status": "unaffected",
"version": "10.2.7 to 10.2.14"
},
{
"status": "unaffected",
"version": "9.2.17 to 9.2.22"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
"versionEndIncluding": "9.4.1",
"versionStartIncluding": "9.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
"versionEndIncluding": "9.3.2",
"versionStartIncluding": "9.3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
"versionEndIncluding": "9.2.15",
"versionStartIncluding": "9.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
"versionEndIncluding": "9.1.1",
"versionStartIncluding": "9.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
"versionEndIncluding": "9.0.3",
"versionStartIncluding": "9.0.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.17:*:*:*:*:*:*:*",
"vulnerable": false
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.18:*:*:*:*:*:*:*",
"vulnerable": false
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.19:*:*:*:*:*:*:*",
"vulnerable": false
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.20:*:*:*:*:*:*:*",
"vulnerable": false
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.21:*:*:*:*:*:*:*",
"vulnerable": false
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.22:*:*:*:*:*:*:*",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center.\r\n\r\nThis DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network.\r\n\r\nAtlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.17\r\n\r\n Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.7\r\n\r\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\r\n\r\nThis vulnerability was reported via our Penetration Testing program."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "DoS (Denial of Service)",
"lang": "en",
"type": "DoS (Denial of Service)"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-21T17:00:00.483Z",
"orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
"shortName": "atlassian"
},
"references": [
{
"url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999345"
},
{
"url": "https://jira.atlassian.com/browse/CONFSERVER-104334"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
"assignerShortName": "atlassian",
"cveId": "CVE-2026-21577",
"datePublished": "2026-07-21T17:00:00.483Z",
"dateReserved": "2026-01-01T00:00:40.721Z",
"dateUpdated": "2026-07-22T18:48:52.568Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"vulnerability-lookup:meta": {
"vulnrichment": {
"containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-21577\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-07-22T18:32:38.139315Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-400\", \"description\": \"CWE-400 Uncontrolled Resource Consumption\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-07-22T18:32:50.393Z\"}}], \"cna\": {\"metrics\": [{\"cvssV4_0\": {\"version\": \"4.0\", \"baseScore\": 7.1, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\"}}], \"affected\": [{\"vendor\": \"Atlassian\", \"product\": \"Confluence Data Center\", \"versions\": [{\"status\": \"affected\", \"version\": \"10.2.0 to 10.2.6\"}, {\"status\": \"affected\", \"version\": \"10.1.0 to 10.1.2\"}, {\"status\": \"affected\", \"version\": \"10.0.2 to 10.0.3\"}, {\"status\": \"affected\", \"version\": \"9.5.1 to 9.5.4\"}, {\"status\": \"affected\", \"version\": \"9.4.0 to 9.4.1\"}, {\"status\": \"affected\", \"version\": \"9.3.1 to 9.3.2\"}, {\"status\": \"affected\", \"version\": \"9.2.0 to 9.2.15\"}, {\"status\": \"affected\", \"version\": \"9.1.0 to 9.1.1\"}, {\"status\": \"affected\", \"version\": \"9.0.1 to 9.0.3\"}, {\"status\": \"unaffected\", \"version\": \"10.2.7 to 10.2.14\"}, {\"status\": \"unaffected\", \"version\": \"9.2.17 to 9.2.22\"}]}], \"references\": [{\"url\": \"https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999345\"}, {\"url\": \"https://jira.atlassian.com/browse/CONFSERVER-104334\"}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center.\\r\\n\\r\\nThis DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network.\\r\\n\\r\\nAtlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\\r\\n Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.17\\r\\n\\r\\n Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.7\\r\\n\\r\\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\\r\\n\\r\\nThis vulnerability was reported via our Penetration Testing program.\"}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"DoS (Denial of Service)\", \"description\": \"DoS (Denial of Service)\"}]}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndIncluding\": \"9.4.1\", \"versionStartIncluding\": \"9.4.0\"}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*\", \"vulnerable\": true}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndIncluding\": \"9.3.2\", \"versionStartIncluding\": \"9.3.1\"}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndIncluding\": \"9.2.15\", \"versionStartIncluding\": \"9.2.0\"}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*\", \"vulnerable\": true}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*\", \"vulnerable\": true}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*\", \"vulnerable\": true}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*\", \"vulnerable\": true}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*\", \"vulnerable\": true}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*\", \"vulnerable\": true}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*\", \"vulnerable\": true}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*\", \"vulnerable\": true}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*\", \"vulnerable\": true}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*\", \"vulnerable\": true}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*\", \"vulnerable\": true}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*\", \"vulnerable\": true}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*\", \"vulnerable\": true}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*\", \"vulnerable\": true}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndIncluding\": \"9.1.1\", \"versionStartIncluding\": \"9.1.0\"}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndIncluding\": \"9.0.3\", \"versionStartIncluding\": \"9.0.1\"}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.17:*:*:*:*:*:*:*\", \"vulnerable\": false}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.18:*:*:*:*:*:*:*\", \"vulnerable\": false}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.19:*:*:*:*:*:*:*\", \"vulnerable\": false}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.20:*:*:*:*:*:*:*\", \"vulnerable\": false}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.21:*:*:*:*:*:*:*\", \"vulnerable\": false}, {\"criteria\": \"cpe:2.3:a:atlassian:confluence_data_center:9.2.22:*:*:*:*:*:*:*\", \"vulnerable\": false}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"f08a6ab8-ed46-4c22-8884-d911ccfe3c66\", \"shortName\": \"atlassian\", \"dateUpdated\": \"2026-07-21T17:00:00.483Z\"}}}",
"cveMetadata": "{\"cveId\": \"CVE-2026-21577\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-07-22T18:48:52.568Z\", \"dateReserved\": \"2026-01-01T00:00:40.721Z\", \"assignerOrgId\": \"f08a6ab8-ed46-4c22-8884-d911ccfe3c66\", \"datePublished\": \"2026-07-21T17:00:00.483Z\", \"assignerShortName\": \"atlassian\"}",
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
}
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…