Record summary

CVE-2021-26072 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.

Description

The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 5, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE ListBefore 5.8.6affected
CVE ListBefore 5.8.6affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMAtlassian Confluence < 5.8.6 - Server-Side Request ForgeryCVSS 4.3

Confluence Server and Data Center before 5.8.6 contain a blind server-side request forgery caused by the WidgetConnector plugin, letting remote attackers manipulate internal network resources, exploit requires network access to the server.

Impact

Authenticated attackers can manipulate internal network resources via SSRF, potentially accessing sensitive internal services or data.

Remediation

Upgrade to Confluence Server version 5.8.6 or later.

WeaknessesCWE-918
AuthorsTechbrunchFR
Template tagscvecve2021confluenceatlassianssrfoastvulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
Shodan: http.component:"Atlassian Confluence"

Source: ProjectDiscovery

References

2