Description
This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center.

This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network.

Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.17

Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.7

See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).

This vulnerability was reported via our Penetration Testing program.
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A recently identified DoS vulnerability exists in Atlassian Confluence Data Center that enables an authenticated attacker to exhaust server resources and render the application unavailable for its intended users. The flaw is classified as a resource exhaustion weakness (CWE-400). Based on the description, it is inferred that the vulnerability is triggered by an attacker exploiting an authenticated session to repeatedly execute privileged operations that consume resources, potentially causing temporary or indefinite service disruption.

Affected Systems

This issue affects Atlassian Confluence Data Center, as detailed by the CNA. Versions impacted include 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0. The advisory recommends that instances running Confluence Data Center 9.2 be upgraded to any release 9.2.17 or later, and that 10.2 installations be upgraded to any release 10.2.7 or later, or to the latest available version overall.

Risk and Exploitability

The CVSS score of 7.1 reflects a moderate to high risk of availability compromise when exploited. The EPSS score of < 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must first be authenticated within Confluence to exploit the flaw, implying an internal threat vector. The likely attack vector is the exploitation of an existing authenticated session to send repeated privileged requests that induce resource exhaustion, leading to denial of service for all users on the affected node.

Generated by OpenCVE AI on August 4, 2026 at 05:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Confluence Data Center to a fixed version, at least 9.2.17 for 9.x releases or 10.2.7 for 10.x releases, or to the latest available release.
  • If an immediate upgrade is not possible, isolate or disable features that consume excessive resources until a patch can be applied.
  • Continuously monitor system metrics such as CPU, memory, and request rates for signs of abnormal or sustained high resource usage that could indicate exploitation.

Generated by OpenCVE AI on August 4, 2026 at 05:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Authenticated Resource Exhaustion DoS in Atlassian Confluence Data Center

Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Authenticated Resource Exhaustion DoS in Atlassian Confluence Data Center

Wed, 29 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title High Severity Denial of Service in Atlassian Confluence Data Center

Fri, 24 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title High Severity Denial of Service in Atlassian Confluence Data Center

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.17 Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.7 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Penetration Testing program.
First Time appeared Atlassian
Atlassian confluence Data Center
CPEs cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.17:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.18:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.19:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.20:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.21:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.22:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*
Vendors & Products Atlassian
Atlassian confluence Data Center
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Atlassian Confluence Data Center
cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published:

Updated: 2026-07-22T18:48:52.568Z

Reserved: 2026-01-01T00:00:40.721Z

Link: CVE-2026-21577

cve-icon Vulnrichment

Updated: 2026-07-22T18:32:50.393Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T18:16:57.327

Modified: 2026-08-10T20:56:11.057

Link: CVE-2026-21577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:45:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption