EIP-2026-102457

PRE-CVE

Atlassian Confluence 6.15.1 - Directory Traversal (Metasploit)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102457. PoCs published by max7253.

AI-analyzed exploit summary This Metasploit module exploits a directory traversal vulnerability (CVE-2019-3398) in Atlassian Confluence 6.15.1 to achieve arbitrary file write and remote code execution by uploading a JSP shellcode file to a traversed path.

Description

Atlassian Confluence 6.15.1 - Directory Traversal (Metasploit)

Exploits (1)

exploitdb WORKING POC
by max7253 · rubywebappsjsp
https://www.exploit-db.com/exploits/47635

This Metasploit module exploits a directory traversal vulnerability (CVE-2019-3398) in Atlassian Confluence 6.15.1 to achieve arbitrary file write and remote code execution by uploading a JSP shellcode file to a traversed path.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Atlassian Confluence 6.15.1
Auth required
Prerequisites: Valid credentials for Confluence · Write permissions on a page · Knowledge of the root directory path
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026