Threat Advisory

Confluence Stored XSS Lets Attackers Run Code and Escalate Privileges

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Atlassian Confluence versions The Confluence flaw affects many Data Center and Server releases, from 7 have been identified in Atlassian Confluence and Jira Service Management Data Center. These flaws pose a critical risk to sensitive project data, allowing attackers to run code in a victim's browser and escalate privileges. The affected version range is from 7.1.1 through 10.2.0 for Confluence and 10.3.0 and 11.3.0 for Jira Service Management.

CVE-2026-21580 (CVSS 9.3 — Critical): A stored XSS bug allows an attacker to run code in a victim's browser, enabling privilege escalation. This vulnerability can expose sensitive project data.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Atlassian Confluence versions The Confluence flaw affects many Data Center and Server releases, from 7 have been identified in Atlassian Confluence and Jira Service Management Data Center. These flaws pose a critical risk to sensitive project data, allowing attackers to run code in a victim's browser and escalate privileges. The affected version range is from 7.1.1 through 10.2.0 for Confluence and 10.3.0 and 11.3.0 for Jira Service Management.

CVE-2026-21580 (CVSS 9.3 — Critical): A stored XSS bug allows an attacker to run code in a victim's browser, enabling privilege escalation. This vulnerability can expose sensitive project data.[emaillocker id="1283"]

CVE-2026-21582: An unauthenticated attacker can act as another user due to a broken authentication and session management bug.

RECOMMENDATIONS:

  • We recommend you to update Confluence to version 9.2.21 or 10.2.13 or later.
  • We recommend you to upgrade Jira Service Management Data Center to version 10.3.24 or 11.3.10 or later.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu