Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
Atlassian — Confluence Server
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
9.8
100.0%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- Aug 30, 2021
- Modified
- Jun 17, 2026
- Added to KEV
- Nov 3, 2021
- Federal patch due
- Nov 17, 2021
CISA required action
Apply updates per vendor instructions.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2021-26084, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- hev0x/CVE-2021-26084_Confluence★ 317
Confluence Server Webwork OGNL injection
updated Jun 28, 2026
- sma11new/PocList★ 178
漏洞POC、EXP合集,持续更新。Apache Druid-任意文件读取(CVE-2021-36749)、ConfluenceRCE(CVE-2021-26084)、ZeroShell防火墙RCE(CVE-2019-12725)、ApacheSolr任意文件读取、蓝凌OA任意文件读取、phpStudyRCE、ShowDoc任意文件上传、原创先锋后台未授权、Kyan账号密码泄露、TerraMasterTos任意文件读取、TamronOS-IPTV系统RCE、Wayos防火墙账号密码泄露
updated Sep 4, 2026
- 0xf4n9x/CVE-2021-26084★ 72
CVE-2021-26084 Remote Code Execution on Confluence Servers
updated Aug 24, 2026
- dinhbaouit/CVE-2021-26084★ 53
updated May 13, 2026
- alt3kx/CVE-2021-26084_PoC★ 53
updated May 4, 2026
- 1ZRR4H/CVE-2021-26084★ 30
Atlassian Confluence CVE-2021-26084 one-liner mass checker
updated Aug 12, 2024
- crowsec-edtech/CVE-2021-26084★ 21
CVE-2021-26084 - Confluence Pre-Auth RCE | OGNL injection
updated Nov 1, 2023
- ZZ-SOCMAP/CVE-2021-26084★ 9
POC of CVE-2021-26084, which is Atlassian Confluence Server OGNL(Object-Graph Navigation Language) Pre-Auth RCE Injection Vulneralibity.
updated Jun 8, 2025
References
Frequently asked questions
What is CVE-2021-26084?
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
How severe is CVE-2021-26084?
CVE-2021-26084 has a CVSS base score of 9.8 out of 10 (CVSS 3.1).
Is CVE-2021-26084 actively exploited in the wild?
Yes. CVE-2021-26084 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Nov 3, 2021, meaning CISA has confirmed evidence of active exploitation. It is also flagged as used in ransomware campaigns.
What is the EPSS score for CVE-2021-26084?
100.0% - meaning FIRST.org's EPSS model estimates a 100.0% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2021-26084?
Yes - a public Nuclei template referencing CVE-2021-26084 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2021-26084?
CVE-2021-26084 is classified under CWE-917 (CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')).
Cross-checked against
Impactr finds and proves whether CVE-2021-26084 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist