CVE-2021-26072
Atlassian Confluence Server and Data Center Server-Side Request Forgery (SSRF)
Record summary
CVE-2021-26072 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.
Description
The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 5, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Confluence Data CenterBrowse Atlassian / Confluence Data Center | CVE List | Before 5.8.6 | affected |
Confluence ServerBrowse Atlassian / Confluence Server | CVE List | Before 5.8.6 | affected |
Confluence Server and Data CenterBrowse Atlassian / Confluence Server and Data Center | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMAtlassian Confluence < 5.8.6 - Server-Side Request ForgeryCVSS 4.3
Confluence Server and Data Center before 5.8.6 contain a blind server-side request forgery caused by the WidgetConnector plugin, letting remote attackers manipulate internal network resources, exploit requires network access to the server.
Impact
Authenticated attackers can manipulate internal network resources via SSRF, potentially accessing sensitive internal services or data.
Remediation
Upgrade to Confluence Server version 5.8.6 or later.
Source: ProjectDiscovery