Vulnerability record · CVE-2019-3396 · published 25 March 2019
CVE-2019-3396: Atlassian Confluence Widget Connector path traversal and RCE via SSTI
Atlassian · Confluence Server
The Widget Connector macro in Atlassian Confluence Server and Data Center fails to safely handle template input, allowing server-side template injection that leads to path traversal and remote code execution. Unauthenticated attackers can reach the vulnerable macro, making this a severe pre-auth flaw for any internet-exposed instance.
Description
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS score of 9.8, active exploitation in KEV, near-maximum EPSS, and known ransomware use.
What it is
The Widget Connector macro in Atlassian Confluence Server and Data Center fails to safely handle template input, allowing server-side template injection that leads to path traversal and remote code execution. Unauthenticated attackers can reach the vulnerable macro, making this a severe pre-auth flaw for any internet-exposed instance.
Impact
An attacker can execute arbitrary code on the Confluence server, leading to full compromise of the host and any data it holds. This can result in data theft, lateral movement, and ransomware deployment.
Attack surface
Reachable over the network through the Widget Connector macro with no authentication or user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any Confluence Server or Data Center instance exposing the vulnerable macro is at risk.
Exploitation
Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS 30-day probability is 0.99913 (99.967th percentile). Multiple public exploit references exist, including Packet Storm, Exploit-DB, and a Rapid7 Metasploit module.
What to do
- Upgrade Confluence Server/Data Center to a fixed version: 6.6.12, 6.12.3, 6.13.3, or 6.14.2 and later as applicable.
- If immediate patching is not possible, restrict network access to Confluence to trusted users and block external exposure.
- Disable or restrict the Widget Connector macro if it is not required.
- Monitor vendor advisories and apply any additional hardening guidance from Atlassian.
- Review for signs of compromise and rotate credentials if exploitation is suspected.
Detection
- Search Confluence and web server logs for requests to widget connector endpoints containing template syntax or path traversal patterns.
- Monitor for unexpected child processes spawned by the Confluence Java process.
- Alert on outbound network connections from the Confluence host to unusual destinations.
- Use file integrity monitoring on Confluence installation and web directories for unexpected changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-3396 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-3396 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-3396), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.