Vulnerability record · CVE-2021-26084 · published 30 August 2021
CVE-2021-26084: Atlassian Confluence Server and Data Center OGNL injection RCE
Atlassian · Confluence Data Center
Confluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker run arbitrary code on the instance. The affected ranges are before 6.13.23, 6.14.0 before 7.4.11, 7.5.0 before 7.11.6, and 7.12.0 before 7.12.5. Because it is remotely reachable without credentials and leads to full code execution, it is a top-tier target for mass exploitation.
Description
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a 9.8 CVSS score, KEV listing, documented ransomware use, and near-maximum EPSS probability makes this an urgent patch-first issue.
What it is
Confluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker run arbitrary code on the instance. The affected ranges are before 6.13.23, 6.14.0 before 7.4.11, 7.5.0 before 7.11.6, and 7.12.0 before 7.12.5. Because it is remotely reachable without credentials and leads to full code execution, it is a top-tier target for mass exploitation.
Impact
An attacker gains arbitrary code execution on the Confluence host, which typically means full control of the application and its data, and a foothold for lateral movement into the internal network.
Attack surface
Reached over the network via HTTP against the Confluence web interface; the CVSS vector shows no privileges required and no user interaction, so exploitation is unauthenticated and remote.
Exploitation
Listed in CISA KEV with a 2021-11-03 addition and a 2021-11-17 remediation due date, and flagged for known ransomware campaign use. EPSS is 0.99999 (99.993rd percentile), and references include an Exploit-tagged third-party advisory, indicating public exploit code exists.
What to do
- Upgrade Confluence Server and Data Center to a fixed release: 6.13.23 or later, 7.4.11 or later, 7.11.6 or later, or 7.12.5 or later.
- If immediate patching is not possible, apply the vendor's interim mitigation guidance from the Atlassian advisory (CONFSERVER-67940) and restrict network access to Confluence.
- Place Confluence behind authentication-aware reverse proxies or VPN and block direct internet exposure of the web interface.
- Rotate credentials and secrets stored or configured in Confluence, and review the instance for unauthorized admin accounts or modified content after any exposure window.
- Monitor for and remove webshells or unexpected files on the Confluence host, and rebuild from a known-good state if compromise is suspected.
Detection
- Review Confluence HTTP access logs for requests containing OGNL expression syntax such as ${, %{, or java.lang.Runtime patterns in query strings or form bodies.
- Alert on unexpected child processes spawned by the Confluence Java process, especially shells, curl, wget, or scripting interpreters.
- Monitor for new or modified files under Confluence web directories and for outbound connections from the Confluence host to unfamiliar external addresses.
- Hunt for anomalous authentication events, new administrative users, and changes to Confluence configuration or plugins following suspicious requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-26084 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Ransomware crews whose documented playbooks reference this CVE: