PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2021-26072

4.3
CVSS
Description

The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.

Attack Vector
-
Privileges Req.
-
User Interaction
-
confluence serverconfluence data center
Updated Sep 18, 2026View on NVD →
S4E scanner

Atlassian Confluence < 5.8.6 - Server-Side Request Forgery

Confluence Server and Data Center before 5.8.6 contain a blind server-side request forgery caused by the WidgetConnector plugin, letting remote attackers manipulate internal network resources, exploit requires network access to the server. References: https://bitbucket.org/atlassian/confluence-business-blueprints/pull-requests/144/issue-60-conf-45342-ssrf-in-sharelinks https://github.com/assetnote/blind-ssrf-chains#confluence https://nvd.nist.gov/vuln/detail/CVE-2021-26072 https://jira.atlassian.com/browse/CONFSERVER-61399

Used 3.4k times · url

CVE history: confluence server

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →