CVE Vulnerabilities

CVE-2021-26085

Direct Request ('Forced Browsing')

Published: Aug 03, 2021 | Modified: Oct 24, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

NameVendorStart VersionEnd Version
Confluence_data_centerAtlassian*7.4.10 (excluding)
Confluence_data_centerAtlassian7.5.0 (including)7.12.3 (excluding)
Confluence_serverAtlassian*7.4.10 (excluding)
Confluence_serverAtlassian7.5.0 (including)7.12.3 (excluding)

Potential Mitigations

References