← Vulnerability feed

Vulnerability record · CVE-2024-21683 · published 21 May 2024

CVE-2024-21683: Atlassian Confluence Data Center and Server code injection RCE

Atlassian · Confluence Data Center

Confluence Data Center and Server contain a code injection flaw introduced in version 5.2 that allows an authenticated attacker to execute arbitrary code. The vulnerability has a CVSS score of 8.8 and requires no user interaction, making it a serious risk for exposed instances.

8.8 CVSS 3.1 High EPSS 88% · top 0.2% CWE-94 · Code injection
8.8CVSS 3.1 base score
88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.  Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the release notes https://confluence.atlassian.com/doc/confluence-release-notes-327.html You can download the latest version of Confluence Data Center and Server from the download center https://www.atlassian.com/software/confluence/download-archives. This vulnerability was found internally.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS score of 8.8 and very high EPSS probability indicate a severe, likely exploitable vulnerability, though it requires authentication.

What it is

Confluence Data Center and Server contain a code injection flaw introduced in version 5.2 that allows an authenticated attacker to execute arbitrary code. The vulnerability has a CVSS score of 8.8 and requires no user interaction, making it a serious risk for exposed instances.

Impact

An authenticated attacker can execute arbitrary code with high impact to confidentiality, integrity, and availability of the Confluence instance. This could lead to full compromise of the application and its data.

Attack surface

The flaw is reachable over the network (AV:N) with low attack complexity (AC:L) and requires low privileges (PR:L) but no user interaction (UI:N). An attacker must have a valid account on the Confluence instance.

Exploitation

The vulnerability is not listed in CISA KEV, but EPSS indicates a very high probability of exploitation (0.88267, 99.76th percentile). No public exploit references are provided in the record.

What to do

  • Upgrade Confluence Data Center and Server to the latest version or a specified supported fixed version as per Atlassian's advisory.
  • If immediate patching is not possible, restrict network access to Confluence instances to trusted users only.
  • Enforce strong authentication and least privilege for Confluence accounts to limit the impact of an authenticated attack.
  • Monitor Atlassian's release notes and security advisories for further updates.

Detection

  • Monitor Confluence application logs for unexpected code execution or suspicious administrative actions.
  • Use network detection to identify unusual outbound connections from Confluence servers that could indicate command and control or data exfiltration.
  • Audit user accounts for unauthorized privilege escalation or creation of new administrative users.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-21683 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-22527Atlassian Confluence Data Center and Server template injection RCEOlder versions of Confluence Data Center and Server contain a template injection flaw (CWE-74) that lets an unauthenticated attacker execute code on …KEVEPSS 100%analysed9.8CVE-2023-22518Atlassian Confluence improper authorization allows admin account creationConfluence Data Center and Server contain an improper authorization flaw that lets an unauthenticated attacker reset Confluence and create an instanc…KEVEPSS 100%analysed9.8CVE-2023-22515Atlassian Confluence Data Center and Server broken access control allows admin account creationConfluence Data Center and Server contain a broken access control flaw that lets an unauthenticated external attacker create unauthorized administrat…KEVEPSS 99%analysed9.8CVE-2022-26134Atlassian Confluence Server and Data Center OGNL injection RCEConfluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker execute arbitrary code on …KEVEPSS 100%analysed9.8CVE-2021-26084Atlassian Confluence Server and Data Center OGNL injection RCEConfluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker run arbitrary code on the …KEVEPSS 100%analysed9.8CVE-2019-3396Atlassian Confluence Widget Connector path traversal and RCE via SSTIThe Widget Connector macro in Atlassian Confluence Server and Data Center fails to safely handle template input, allowing server-side template inject…KEVEPSS 100%analysed8.8CVE-2019-3398Atlassian Confluence Server path traversal in downloadallattachmentsConfluence Server and Data Center contain a path traversal flaw in the downloadallattachments resource. An attacker with permission to add attachment…KEVEPSS 97%analysed5.3CVE-2021-26086Atlassian Jira Server and Data Center path traversal file readJira Server and Data Center contain a path traversal flaw in the /WEB-INF/web.xml endpoint that lets remote attackers read particular files. The affe…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2024-21683), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.