S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Oct 8, 2025

CVE-2021-26072 Scanner

CVE-2021-26072 Scanner - Server-Side Request Forgery vulnerability in Atlassian Confluence

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-26072
4.3
CVSS

The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Confluence Serverby Atlassian
AFFECTED< 5.8.6SAFE ✓≥ 5.8.6
Confluence Data Centerby Atlassian
AFFECTED< 5.8.6SAFE ✓≥ 5.8.6
Updated Aug 19, 2026View on NVD →
Detail

Atlassian Confluence is used in enterprises and development environments as a collaboration and documentation platform where teams can create, share, and manage files in a secure space. It is typically deployed by IT departments within various organizations across different industries. The main purpose of Atlassian Confluence is to facilitate internal knowledge sharing and project management. Organizations utilize it to improve team productivity through streamlined communication and documentation processes. Confluence integrates with other Atlassian products, making it a versatile tool for software development and project management teams. It is widely adaptable to different team sizes, ranging from small businesses to large enterprises.

The Server-Side Request Forgery (SSRF) vulnerability allows attackers to make requests to unauthorized resources within an internal network. This particular SSRF in Atlassian Confluence can lead to unauthorized access to internal systems and data leakage. An attacker with network access can exploit this flaw through the WidgetConnector plugin. The vulnerability requires the attacker to have some level of authentication to perform the exploit. An SSRF can lead to potentially critical security breaches if leveraged to further compromise a network. Unchecked, this vulnerability can impact confidentiality and the integrity of an organization's internal networks.

Technical exploitation of this vulnerability involves sending a crafted request to the vulnerable endpoint used by the WidgetConnector plugin. Attackers manipulate the 'url' parameter to initiate requests to internal systems from the Confluence server itself. The vulnerable endpoint is '/rest/sharelinks/1.0/link' where 'url' parameter needs to be controlled. By altering this parameter, attackers can trick Confluence into forwarding requests internally, bypassing network access restrictions. This attack can further be linked with previously known internal vulnerabilities, increasing potential damage. Such attacks require manipulation of HTTP responses to gather relevant information from internal services, detected via interaction with external services like Interactsh.

If this vulnerability is exploited, it can lead to unauthorized access to internal applications and data exposure. Attackers could further exploit this access to escalate privileges or map the internal network structure. It could lead to the disclosure of sensitive data and configuration details, potentially compromising the security of internal services. While it doesn't directly provide control over other systems, it opens pathways for further attacks such as leveraging SSRF to reach other services. The potential effect of this vulnerability broadens if combined with other weaknesses in the network. The overall network integrity and security posture of an organization might be significantly compromised.

REFERENCES

Solution Advice
  • Upgrade Atlassian Confluence to version 5.8.6 or later, where the vulnerability is patched.
  • Implement network-level restrictions to prevent undue access to internal services by unauthorized users.
  • Regularly audit and monitor server logs to detect unusual request patterns indicative of SSRF.
  • Use web application firewalls (WAF) to detect and block potential SSRF attacks.
  • Conduct regular security assessments to identify and mitigate other potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.