← Vulnerability feed

Vulnerability record · CVE-2019-3396 · published 25 March 2019

CVE-2019-3396: Atlassian Confluence Widget Connector path traversal and RCE via SSTI

Atlassian · Confluence Server

The Widget Connector macro in Atlassian Confluence Server and Data Center fails to safely handle template input, allowing server-side template injection that leads to path traversal and remote code execution. Unauthenticated attackers can reach the vulnerable macro, making this a severe pre-auth flaw for any internet-exposed instance.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1% CWE-22 · Path traversal
9.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
11References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS score of 9.8, active exploitation in KEV, near-maximum EPSS, and known ransomware use.

What it is

The Widget Connector macro in Atlassian Confluence Server and Data Center fails to safely handle template input, allowing server-side template injection that leads to path traversal and remote code execution. Unauthenticated attackers can reach the vulnerable macro, making this a severe pre-auth flaw for any internet-exposed instance.

Impact

An attacker can execute arbitrary code on the Confluence server, leading to full compromise of the host and any data it holds. This can result in data theft, lateral movement, and ransomware deployment.

Attack surface

Reachable over the network through the Widget Connector macro with no authentication or user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any Confluence Server or Data Center instance exposing the vulnerable macro is at risk.

Exploitation

Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS 30-day probability is 0.99913 (99.967th percentile). Multiple public exploit references exist, including Packet Storm, Exploit-DB, and a Rapid7 Metasploit module.

What to do

  • Upgrade Confluence Server/Data Center to a fixed version: 6.6.12, 6.12.3, 6.13.3, or 6.14.2 and later as applicable.
  • If immediate patching is not possible, restrict network access to Confluence to trusted users and block external exposure.
  • Disable or restrict the Widget Connector macro if it is not required.
  • Monitor vendor advisories and apply any additional hardening guidance from Atlassian.
  • Review for signs of compromise and rotate credentials if exploitation is suspected.

Detection

  • Search Confluence and web server logs for requests to widget connector endpoints containing template syntax or path traversal patterns.
  • Monitor for unexpected child processes spawned by the Confluence Java process.
  • Alert on outbound network connections from the Confluence host to unusual destinations.
  • Use file integrity monitoring on Confluence installation and web directories for unexpected changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-3396 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-3396 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-22527Atlassian Confluence Data Center and Server template injection RCEOlder versions of Confluence Data Center and Server contain a template injection flaw (CWE-74) that lets an unauthenticated attacker execute code on …KEVEPSS 100%analysed9.8CVE-2023-22518Atlassian Confluence improper authorization allows admin account creationConfluence Data Center and Server contain an improper authorization flaw that lets an unauthenticated attacker reset Confluence and create an instanc…KEVEPSS 100%analysed9.8CVE-2023-22515Atlassian Confluence Data Center and Server broken access control allows admin account creationConfluence Data Center and Server contain a broken access control flaw that lets an unauthenticated external attacker create unauthorized administrat…KEVEPSS 99%analysed9.8CVE-2022-26134Atlassian Confluence Server and Data Center OGNL injection RCEConfluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker execute arbitrary code on …KEVEPSS 100%analysed9.8CVE-2021-26084Atlassian Confluence Server and Data Center OGNL injection RCEConfluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker run arbitrary code on the …KEVEPSS 100%analysed8.8CVE-2019-3398Atlassian Confluence Server path traversal in downloadallattachmentsConfluence Server and Data Center contain a path traversal flaw in the downloadallattachments resource. An attacker with permission to add attachment…KEVEPSS 97%analysed5.3CVE-2021-26085Atlassian Confluence Server pre-auth arbitrary file read via /s/ endpointConfluence Server and Data Center expose a pre-authorization arbitrary file read through the /s/ endpoint, letting unauthenticated remote attackers v…KEVEPSS 100%analysed9.8CVE-2022-26136Atlassian bamboo improper authentication vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps…EPSS 5.4%

Source: NIST National Vulnerability Database (record CVE-2019-3396), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.