CVE-2026-53434 – Confluence
“Critical dependency flaws can turn crafted content into service disruption, unauthorized file access, and weakened security controls.”
Confluence is affected by nine dependency vulnerabilities spanning resource exhaustion, path traversal, file disclosure, cryptographic weaknesses, and improper error handling. CVE-2026-59873, CVE-2026-53434, and CVE-2025-14813 have CVSS scores of 9.2, 9.1, and 9.3 respectively, all Critical severity. CVE-2026-59874 and CVE-2026-48801 are 8.7, High severity; CVE-2026-29786 is 8.2, High severity; and CVE-2026-59887 and CVE-2026-45623 are 7.5, High severity. CVE-2026-59871 has a CVSS score of 5.3, Medium severity.
Public proof-of-concept information is available for seven vulnerabilities. Impact includes CPU and disk exhaustion, application denial of service, writes outside intended extraction directories, local file disclosure, and path-based security weaknesses.
Key Details
- Affected Product
- Apache Tomcat
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-390