Summary
CVE-2026-21579 is a high-severity unauthenticated Information Disclosure vulnerability in Atlassian Confluence Data Center, rated CVSS 4.0 score 8.2 (High). An unauthenticated remote attacker can exploit this flaw over the network to view sensitive information, with no privileges or user interaction required. Atlassian published the advisory on July 21, 2026 and recommends immediate upgrade to the specified fixed releases.
Technical details
- Root cause: The vulnerability was introduced across multiple major release lines of Confluence Data Center. Atlassian has not disclosed the specific component or code path responsible; the flaw enables access to sensitive information without authentication.
- Trigger conditions: The CVSS 4.0 vector includes AT:P (Attack Requirements: Present), indicating that a specific precondition must exist on the target instance for exploitation to succeed. Atlassian has not publicly described the required configuration.
- Attack vector: Network-reachable (AV:N); no authentication (PR:N) and no user interaction (UI:N) required. Attack complexity is low (AC:L).
- Impact: Successful exploitation results in High Confidentiality impact (VC:H) on the vulnerable component. Integrity and availability are not affected (VI:N, VA:N). No impact on the subsequent system is indicated (SC:N, SI:N, SA:N).
Affected software
- Confluence Data Center 7.19.26 – 7.19.30
- Confluence Data Center 8.5.14 – 8.5.31
- Confluence Data Center 8.9.5 – 8.9.8
- Confluence Data Center 9.0.1 – 9.0.3
- Confluence Data Center 9.1.0 – 9.1.1
- Confluence Data Center 9.2.0 – 9.2.21
- Confluence Data Center 10.0.2 – 10.0.3
- Confluence Data Center 10.1.0 – 10.1.2
- Confluence Data Center 10.2.0 – 10.2.13
Severity
CVSS 4.0 Base Score: 8.2 (High)
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Note: A CVSS v3.1 score has not been published for this vulnerability at time of writing.
Mitigation and recommended actions
- Immediate – upgrade to a fixed release:
- Confluence Data Center 9.2.22 or later (within the 9.2.x line)
- Confluence Data Center 10.2.14 or later (within the 10.2.x line)
- Or the latest generally available release
- Atlassian has not published any workaround or configuration-level mitigation; upgrading to a fixed version is the sole recommended remediation.
- Administrators unable to upgrade immediately should consider restricting network access to Confluence Data Center instances from the public internet as a temporary risk-reduction measure.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

