Multiple security vulnerabilities affecting Atlassian Confluence versions The Confluence flaw affects many Data Center and Server releases, from 7 have been identified in Atlassian Confluence and Jira Service Management Data Center. These flaws pose a critical risk to sensitive project data, allowing attackers to run code in a victim's browser and escalate privileges. The affected version range is from 7.1.1 through 10.2.0 for Confluence and 10.3.0 and 11.3.0 for Jira Service Management.
CVE-2026-21580 (CVSS 9.3 — Critical): A stored XSS bug allows an attacker to run code in a victim's browser, enabling privilege escalation. This vulnerability can expose sensitive project data.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting Atlassian Confluence versions The Confluence flaw affects many Data Center and Server releases, from 7 have been identified in Atlassian Confluence and Jira Service Management Data Center. These flaws pose a critical risk to sensitive project data, allowing attackers to run code in a victim's browser and escalate privileges. The affected version range is from 7.1.1 through 10.2.0 for Confluence and 10.3.0 and 11.3.0 for Jira Service Management.
CVE-2026-21580 (CVSS 9.3 — Critical): A stored XSS bug allows an attacker to run code in a victim's browser, enabling privilege escalation. This vulnerability can expose sensitive project data.[emaillocker id="1283"]
CVE-2026-21582: An unauthenticated attacker can act as another user due to a broken authentication and session management bug.
The following reports contain further technical details:
[/emaillocker]