以下是该漏洞描述的中文翻译: 这是一个高严重性的身份验证不当(Improper Authorization)漏洞,存在于 Confluence Data Center 的以下版本中:7.4.0、7.13.0、8.5.0、8.9.0、9.0.1、9.1.0、9.2.0、9.3.1、9.4.0、9.5.1、10.0.2、10.1.0 和 10.2.0。 该身份验证不当漏洞的 CVSS 评分为 7.1,允许经过身份验证的攻击者获取非预期的访问权限,可能导致资源或功能被非预期地暴露,从而使攻击者有可能获取敏感信息,甚至执行
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Atlassian | Confluence Data Center | 10.2.1 to 10.2.15 |
affected |
10.1.0 to 10.1.2 |
affected | ||
10.0.2 to 10.0.3 |
affected | ||
9.5.1 to 9.5.4 |
affected | ||
9.4.0 to 9.4.1 |
affected | ||
9.3.1 to 9.3.2 |
affected | ||
9.2.0 to 9.2.23 |
affected | ||
9.1.1 |
affected | ||
| … +5 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Atlassian | Confluence Data Center | 10.2.1 to 10.2.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-21588 | 7.1 HIGH | CVE-2026-21588 |
| CVE-2026-21587 | 7.1 HIGH | CVE-2026-21587 |
No comments yet