CVE-2019-3398

HIGH KEV NUCLEI

Confluence Server 6.15.1 - Path Traversal and Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-3398 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021. EIP tracks 3 public exploits from researchers including max7253, superevr, 132231g. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability (CVE-2019-3398) in Atlassian Confluence 6.15.1 to achieve arbitrary file write, allowing an attacker to upload a webshell. It authenticates, retrieves an Atlassian token, and exploits the path traversal to place the shell in the web root.

Description

Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability.

Exploits (3)

exploitdb WORKING POC
by max7253 · pythonwebappsjsp
https://www.exploit-db.com/exploits/47621

This exploit leverages a directory traversal vulnerability (CVE-2019-3398) in Atlassian Confluence 6.15.1 to achieve arbitrary file write, allowing an attacker to upload a webshell. It authenticates, retrieves an Atlassian token, and exploits the path traversal to place the shell in the web root.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Atlassian Confluence 6.15.1
Auth required
Prerequisites: Valid credentials for Confluence · Network access to the target · Write permissions in the web root or a traversable path
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 15 stars
by superevr · remote-auth
https://github.com/superevr/cve-2019-3398

This PoC exploits CVE-2019-3398 in Atlassian Confluence by uploading a malicious JSP shell via a path traversal vulnerability in the drag-and-drop upload feature. It requires valid credentials and leverages a CSRF token to bypass protections.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Atlassian Confluence 6.12.3, 6.13.3, 6.14.2, 6.15.1
Auth required
Prerequisites: Valid Confluence credentials · Network access to the target · Path traversal vulnerability in upload feature
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by 132231g · remote
https://github.com/132231g/CVE-2019-3398

This YAML-based PoC for CVE-2019-3398 exploits a directory traversal vulnerability in Confluence to upload a JSP shell. It includes authentication, token extraction, and multi-step exploitation to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Atlassian Confluence (versions affected by CVE-2019-3398)
Auth required
Prerequisites: Valid credentials for Confluence · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Atlassian Confluence Download Attachments - Remote Code Execution
HIGHby rootxharsh,iamnoooob,pdresearch
Shodan: http.component:"atlassian confluence" || cpe:"cpe:2.3:a:atlassian:confluence"

References (7)

Core 7
Core References
Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/CONFSERVER-58102
Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Apr/33
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108067

Scores

CVSS v3 8.8
EPSS 0.9385
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-11-03
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2019-13037
CWE
CWE-22
Status published
Products (1)
atlassian/confluence_server 2.0 - 6.6.13
Published Apr 18, 2019
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026