Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-26073

24
FAUCET Score

CVE-2021-26073 is a Broken Authentication vulnerability in Atlassian Connect Express (ACE) versions 3.0.2 through 6.5.x. It allows an attacker to send authenticated re-installation events to an ACE app by exploiting the erroneous acceptance of context JWTs in lifecycle endpoints, where only server-to-server JWTs should be processed. This vulnerability has a CVSS score of 7.7 (High), indicating a network-based attack with low complexity, requiring low privileges, and resulting in high integrity impact without confidentiality or availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, with only one mention and one media article identified.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.2, < 6.6.0CPE matchmatch criteria
cpe:2.3:a:atlassian:connect_express:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.1
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.92%
Probability of exploitation in next 30 days
EPSS Percentile
56.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0092 is in the 52nd percentile among its peer group of 17,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

npmpatch availablevia ghsa
Product: atlassian-connect-expressFixed in: 6.6.0

Vendor Advisories (1)

npmGHSA-4v96-m8xv-x83vhigh

Broken Authentication in Atlassian Connect Express

May 24, 2022

References

community.developer.atlassian.com / t/action-required-atlassian-connect-vulnerability-a%5B%E2%80%A6%5Dypass-of-app-qsh-verification-via-context-jwts/47072
confluence.atlassian.com / pages/viewpage.action
Vendor Advisory
security.netapp.com / advisory/ntap-20210604-0004
Third Party Advisory