Junglewise Threat Intelligence

CVE-2021-26084: Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

CVE-2021-26084 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Atlassian Confluence Data Center, Atlassian Data Center, Atlassian Confluence Server. Vendors: Atlassian.

Executive brief

Atlassian Confluence Server and Data Center are vulnerable to an Object-Graph Navigation Language (OGNL) injection. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary code on the affected instance.

Affected products

  • Atlassian Confluence Server before 6.13.23, 6.14.0 to 7.4.11, 7.5.0 to 7.11.6, 7.12.0 to 7.12.5
  • Atlassian Confluence Data Center before 6.13.23, 6.14.0 to 7.4.11, 7.5.0 to 7.11.6, 7.12.0 to 7.12.5

Timeline

  • 2021-11-03: disclosed: Vulnerability published and added to CISA KEV catalog.
  • 2021-11-03: kev added
  • 2021-11-03: exploited: Reported as exploited in the wild.

Related threats