Loading
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.
Use CWE-425, Atlassian vendor hub and Confluence Data Center product page to widen CVE-2021-26085 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-22527, CVE-2024-21683 and CVE-2024-21677 for nearby disclosures in the same product family.