Impact
This vulnerability is a case of improper authorization, allowing an authenticated user to obtain privileges or access resources beyond what the system intends bypasses the intended permission checks. The likely attack vector is an authenticated attacker using an existing user account; initial system compromise is not required. Successful exploitation can expose sensitive information or, in some contexts, enable arbitrary code execution depending on the elevated privileges granted.
Affected Systems
Atlassian Confluence Data Center is affected. Versions impacted include 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0. Atlassian recommends upgrading to the latest release. Specifically, users on Confluence 9.2.24 or later, and users on Confluence 10.2 should upgrade to 10.2.17 or later.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium to high level of risk. Because the attack requires only authenticated access, an attacker with valid user credentials can exploit the flaw without additional privileges. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, so there is no evidence of public exploitation yet data or obtain elevated privileges makes the risk significant, especially in environments where Confluence is reachable from untrusted networks.
OpenCVE Enrichment