CVE-2021-26084

CRITICAL KEV RANSOMWARE NUCLEI LAB

Atlassian Confluence Server and Data Center - OGNL Injection

Title source: llm

Description

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

Exploits (41)

exploitdb WORKING POC
by Fellipe Oliveira · pythonwebappsjava
https://www.exploit-db.com/exploits/50243
nomisec WORKING POC 315 stars
by hev0x · remote
https://github.com/hev0x/CVE-2021-26084_Confluence
nomisec WORKING POC 72 stars
by 0xf4n9x · remote
https://github.com/0xf4n9x/CVE-2021-26084
nomisec WORKING POC 54 stars
by dinhbaouit · remote
https://github.com/dinhbaouit/CVE-2021-26084
nomisec WRITEUP 54 stars
by alt3kx · remote
https://github.com/alt3kx/CVE-2021-26084_PoC
nomisec SCANNER 30 stars
by 1ZRR4H · poc
https://github.com/1ZRR4H/CVE-2021-26084
nomisec WORKING POC 21 stars
by crowsec-edtech · poc
https://github.com/crowsec-edtech/CVE-2021-26084
nomisec SUSPICIOUS 9 stars
by Vulnmachines · remote
https://github.com/Vulnmachines/Confluence_CVE-2021-26084
nomisec WORKING POC 8 stars
by taythebot · remote
https://github.com/taythebot/CVE-2021-26084
nomisec WORKING POC 7 stars
by lleavesl · remote
https://github.com/lleavesl/CVE-2021-26084
nomisec WORKING POC 5 stars
by BBD-YZZ · remote
https://github.com/BBD-YZZ/Confluence-RCE
nomisec WORKING POC 5 stars
by JKme · remote
https://github.com/JKme/CVE-2021-26084
nomisec WRITEUP 4 stars
by orangmuda · remote
https://github.com/orangmuda/CVE-2021-26084
nomisec WORKING POC 3 stars
by ludy-dev · remote
https://github.com/ludy-dev/CVE-2021-26084_PoC
nomisec SUSPICIOUS 3 stars
by Loneyers · poc
https://github.com/Loneyers/CVE-2021-26084
nomisec SCANNER 3 stars
by BeRserKerSec · remote
https://github.com/BeRserKerSec/CVE-2021-26084-Nuclei-template
nomisec WORKING POC 2 stars
by toowoxx · poc
https://github.com/toowoxx/docker-confluence-patched
nomisec WRITEUP 1 stars
by nahcusira · poc
https://github.com/nahcusira/CVE-2021-26084
nomisec WORKING POC 1 stars
by Jun-5heng · remote
https://github.com/Jun-5heng/CVE-2021-26084
nomisec WRITEUP 1 stars
by nizar0x1f · poc
https://github.com/nizar0x1f/CVE-2021-26084-patch-
nomisec WORKING POC 1 stars
by TheclaMcentire · remote
https://github.com/TheclaMcentire/CVE-2021-26084_Confluence
nomisec WORKING POC 1 stars
by GlennPegden2 · remote
https://github.com/GlennPegden2/cve-2021-26084-confluence
nomisec WORKING POC 1 stars
by bcdannyboy · remote
https://github.com/bcdannyboy/CVE-2021-26084_GoPOC
nomisec WORKING POC 1 stars
by prettyrecon · poc
https://github.com/prettyrecon/CVE-2021-26084_Confluence
nomisec SCANNER
by quesodipesto · poc
https://github.com/quesodipesto/conflucheck
nomisec WRITEUP
by wdjcy · poc
https://github.com/wdjcy/CVE-2021-26084
nomisec WORKING POC
by attacker-codeninja · poc
https://github.com/attacker-codeninja/CVE-2021-26084
nomisec STUB
by wolf1892 · poc
https://github.com/wolf1892/confluence-rce-poc
nomisec STUB
by p0nymc1 · poc
https://github.com/p0nymc1/CVE-2021-26084
nomisec WORKING POC
by Xc1Ym · remote
https://github.com/Xc1Ym/cve_2021_26084
nomisec STUB
by 30579096 · poc
https://github.com/30579096/Confluence-CVE-2021-26084
nomisec WORKING POC
by maskerTUI · remote
https://github.com/maskerTUI/CVE-2021-26084
nomisec WORKING POC
by smallpiggy · remote
https://github.com/smallpiggy/cve-2021-26084-confluence
nomisec WORKING POC
by CrackerCat · poc
https://github.com/CrackerCat/CVE-2021-26084
nomisec WORKING POC
by b1gw00d · poc
https://github.com/b1gw00d/CVE-2021-26084
nomisec SCANNER
by Osyanina · poc
https://github.com/Osyanina/westone-CVE-2021-26084-scanner
vulncheck_xdb WORKING POC
remote
https://github.com/sma11new/PocList
vulncheck_xdb WORKING POC
remote
https://github.com/httpvoid/CVE-Reverse
metasploit WORKING POC EXCELLENT
by Benny Jacob, Jang, wvu · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/atlassian_confluence_webwork_ognl_injection.rb

Nuclei Templates (1)

Confluence Server - Remote Code Execution
CRITICALby dhiyaneshDk,philippedelteil
Shodan: http.component:"Atlassian Confluence" || http.component:"atlassian confluence"
FOFA: app="atlassian-confluence"

Scores

CVSS v3 9.8
EPSS 0.9444
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull atlassian/confluence-server:7.3
docker pull atlassian/confluence:7.12.2
docker pull wdjcy/confluence
+35 more repos

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-09-08
InTheWild.io 2021-09-24
ENISA EUVD EUVD-2021-12905
Ransomware Use Confirmed
CWE
CWE-917
Status published
Products (2)
atlassian/confluence_data_center < 6.13.23
atlassian/confluence_server < 6.13.23
Published Aug 30, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026