← Browse CVEs
CVE-2021-26085
Medium · CVSS 5.3EPSS 99.9%CISA KEVCWE-425
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.
References
Published
Community ground truth
Community verdict
3 verdictsNot a real issue
to add your verdict.
Community real-world severity: Critical (Critical 3) — CVSS base score 5.3
Practitioners rate this higher than its CVSS — treat with extra caution.
Field notes & remediation
Verdicts are the quick signal — notes are the evidence and fixes behind them.
No notes yet — be the first to share what you saw or a fix that worked.