← Vulnerability feed

Vulnerability record · CVE-2019-3398 · published 18 April 2019

CVE-2019-3398: Atlassian Confluence Server path traversal in downloadallattachments

Atlassian · Confluence Server

Confluence Server and Data Center contain a path traversal flaw in the downloadallattachments resource. An attacker with permission to add attachments, create spaces, or hold space Admin rights can write files to arbitrary locations, which can lead to remote code execution. It matters because the required privilege is common in normal Confluence use, and the flaw is listed in CISA KEV with a very high EPSS score.

8.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 97% · top 0.1% CWE-22 · Path traversal
8.8CVSS 3.1 base score, v2 9.0
97%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
13References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe flaw allows authenticated remote code execution, is listed in CISA KEV, and has an EPSS probability above 0.96, so it is being actively exploited.

What it is

Confluence Server and Data Center contain a path traversal flaw in the downloadallattachments resource. An attacker with permission to add attachments, create spaces, or hold space Admin rights can write files to arbitrary locations, which can lead to remote code execution. It matters because the required privilege is common in normal Confluence use, and the flaw is listed in CISA KEV with a very high EPSS score.

Impact

An attacker gains arbitrary file write on the Confluence host, which can be leveraged to execute code and take over the server. This can expose or destroy all content and credentials the instance holds.

Attack surface

Reachable over the network through the Confluence web interface; no user interaction is required, but the attacker must hold an authenticated account with attachment, space creation, or space Admin permissions.

Exploitation

CVE-2019-3398 is in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of 0.96837 (99.885th percentile), indicating active exploitation. Public exploit references exist, though no ransomware group is documented as using it.

What to do

  • Upgrade Confluence Server and Data Center to a fixed release: 6.6.13, 6.12.4, 6.13.4, 6.14.3, or 6.15.2 and later.
  • If immediate patching is not possible, restrict who can add attachments, create spaces, or hold space Admin rights.
  • Limit network exposure of Confluence to trusted users and networks.
  • Review and remove unnecessary space Admin and attachment permissions from untrusted accounts.
  • Monitor vendor advisories for any further guidance on this issue.

Detection

  • Review Confluence access logs for requests to the downloadallattachments resource with traversal sequences such as ../ or encoded variants.
  • Alert on file writes or new files appearing in web-accessible or unexpected directories on the Confluence host.
  • Monitor for unexpected child processes spawned by the Confluence Java process.
  • Audit accounts granted attachment, space creation, or space Admin permissions for unexpected changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-3398 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Atlassian Confluence Server and Data Center Path Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-3398 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-22527Atlassian Confluence Data Center and Server template injection RCEOlder versions of Confluence Data Center and Server contain a template injection flaw (CWE-74) that lets an unauthenticated attacker execute code on …KEVEPSS 100%analysed9.8CVE-2023-22518Atlassian Confluence improper authorization allows admin account creationConfluence Data Center and Server contain an improper authorization flaw that lets an unauthenticated attacker reset Confluence and create an instanc…KEVEPSS 100%analysed9.8CVE-2023-22515Atlassian Confluence Data Center and Server broken access control allows admin account creationConfluence Data Center and Server contain a broken access control flaw that lets an unauthenticated external attacker create unauthorized administrat…KEVEPSS 99%analysed9.8CVE-2022-26134Atlassian Confluence Server and Data Center OGNL injection RCEConfluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker execute arbitrary code on …KEVEPSS 100%analysed9.8CVE-2021-26084Atlassian Confluence Server and Data Center OGNL injection RCEConfluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker run arbitrary code on the …KEVEPSS 100%analysed9.8CVE-2019-3396Atlassian Confluence Widget Connector path traversal and RCE via SSTIThe Widget Connector macro in Atlassian Confluence Server and Data Center fails to safely handle template input, allowing server-side template inject…KEVEPSS 100%analysed5.3CVE-2021-26085Atlassian Confluence Server pre-auth arbitrary file read via /s/ endpointConfluence Server and Data Center expose a pre-authorization arbitrary file read through the /s/ endpoint, letting unauthenticated remote attackers v…KEVEPSS 100%analysed9.8CVE-2022-26136Atlassian bamboo improper authentication vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps…EPSS 5.4%

Source: NIST National Vulnerability Database (record CVE-2019-3398), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.