Description
This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center.

This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network.

Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.24

Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.17

See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).

This vulnerability was reported via our Penetration Testing program.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Upgrade
AI Analysis

Impact

Atlassian Confluence Data Center contains a flaw that allows an authenticated user to trigger a denial of service by exhausting application resources. The vulnerability is rated CVSS 7.1 and is mapped to CWE-400. An attacker with valid credentials can generate requests that cause the Confluence process to become unresponsive or crash, making the service unavailable to legitimate users for a temporary or indefinite period.

Affected Systems

The issue impacts Confluence Data Center releases beginning with 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0. Based on the vendor recommendation, versions 9.2.24 and later, and 10.2.17 and later are not affected; therefore, the vulnerability likely exists in releases through 9.2.23 and 10.2.16 (inference). Users on these affected releases should not operate unless they apply the patched version. Atlassian recommends upgrading to 9.2.24 or later for the 9.2 series, and to 10.2.17 or later for the 10.2 series, or to the latest available release.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, yet the EPSS score of < 1% shows a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the attacker requires authentication, the risk is mitigated by user credential controls, but once authenticated, the flaw can be leveraged to disrupt service. Organizations should treat this as a priority issue and implement the vendor’s fix promptly to prevent potential service outages.

Generated by OpenCVE AI on September 20, 2026 at 15:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Confluence Data Center to version 9.2.24 or later on the 9.2 series, or to 10.2.17 or later on the 10.2 series.
  • If an immediate upgrade is not possible, restrict external access to the Confluence instance, apply additional rate–limiting for authenticated sessions, and monitor the system for abnormal request patterns.
  • After applying the fix or implementing mitigations, conduct a controlled load test to verify that the denial‑of‑service path has been eliminated.

Generated by OpenCVE AI on September 20, 2026 at 15:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Authenticated Denial of Service in Atlassian Confluence Data Center

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Title Authenticated Denial of Service in Atlassian Confluence Data Center

Wed, 16 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Title Authenticated Denial of Service in Atlassian Confluence Data Center

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.24 Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.17 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Penetration Testing program.
First Time appeared Atlassian
Atlassian confluence Data Center
CPEs cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.16:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.17:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.18:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.19:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.20:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.21:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.22:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.23:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.24:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.25:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*
Vendors & Products Atlassian
Atlassian confluence Data Center
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Atlassian Confluence Data Center
cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published:

Updated: 2026-09-15T23:21:14.322Z

Reserved: 2026-01-01T00:00:40.722Z

Link: CVE-2026-21588

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:18.621Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T17:17:12.020

Modified: 2026-09-16T19:10:48.873

Link: CVE-2026-21588

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:15:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption