CVE-2021-26084
Atlassian Confluence Server, Atlassian Confluence Data Center
Published 30 Aug 2021 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 17 Nov 2021 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply updates per vendor instructions.
Description
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
References
- packetstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGNL-Injection.html · Exploit, Third Party Advisory, VDB Entry
- jira.atlassian.com/browse/CONFSERVER-67940 · Issue Tracking, Patch, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26084 · US Government Resource