LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-26085: Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 28, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 18, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-26085 to its Known Exploited Vulnerabilities catalog on Mar 28, 2022, with a federal patch deadline of Apr 18, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

CVE-2021-26085 is a pre-authorization arbitrary file read vulnerability in Atlassian Confluence Server. It allows remote attackers to view restricted resources through the /s/ endpoint without authenticating first. Because the flaw requires no prior login and has been tied to known ransomware activity, unpatched Confluence Server instances exposed to untrusted networks present a direct risk of sensitive data exposure and follow-on compromise.

Defenders should treat this as a high-priority inventory and remediation item. Confirm exact affected versions, fixed releases, and any configuration prerequisites against the official Atlassian advisory before acting.

How it works

The weakness is classified as CWE-425 (Direct Request / Forced Browsing). In this class of flaw, an application fails to enforce authorization checks on certain URLs or resources, so an attacker who knows or guesses a path can retrieve content that should be restricted.

According to the CISA summary, affected versions of Atlassian Confluence Server permit remote attackers to view restricted resources via a pre-authorization arbitrary file read in the /s/ endpoint. An unauthenticated attacker sends crafted requests to that endpoint and can read files or other resources the application would normally protect. Public detail on exact request structure and file-system reach is limited; treat any exploit descriptions outside the vendor advisory as unverified. The practical impact is unauthorized disclosure of configuration files, credentials, or other sensitive data that may later enable privilege escalation or ransomware deployment.

Am I affected? How to find it in your systems

Atlassian Confluence Server is commonly deployed as an internal or externally reachable collaboration wiki, often on Linux or Windows hosts behind a reverse proxy or load balancer. It may appear in application portfolios under names such as Confluence, wiki, or knowledge-base services.

How to remediate

Patch first. Apply the updates specified by Atlassian for CVE-2021-26085 exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Implement compensating controls to reduce exposure until the vendor update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities, especially those with documented ransomware use, frequently lead to data theft and extortion. If logs or other indicators suggest the /s/ endpoint was abused, assume restricted resources may have been read and begin incident-response procedures: isolate the host, preserve logs, rotate secrets, and assess downstream systems that trust Confluence data. You can also run a free exposure scan of your email addresses against known breach datasets to determine whether associated credentials have appeared in prior public dumps, then force password resets and enable multi-factor authentication where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAtlassian · Confluence Server
WeaknessCWE-425
Added to CISA KEVMar 28, 2022
Federal patch deadlineApr 18, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities