Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-26084

Quick assessment

Affected
Atlassian Confluence Server
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Atlassian Confluence Server是澳大利亚Atlassian公司的一套具有企业知识管理功能,并支持用于构建企业WiKi的协同软件的服务器版本。 Atlassian Confluence Server and Data Center 存在注入漏洞,经过身份验证的用户在Confluence 服务器或数据中心实例上执行任意代码。以下产品及版本收到影响:All 4.x.x versions、All 5.x.x versions、All 6.0.x versions、All 6.1.x ver

AI Predicted 9.8 Difficulty: Easy KEV · Ransomware EPSS 100.00% · P100

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-26084

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Atlassian Confluence Server 注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Atlassian Confluence Server是澳大利亚Atlassian公司的一套具有企业知识管理功能,并支持用于构建企业WiKi的协同软件的服务器版本。 Atlassian Confluence Server and Data Center 存在注入漏洞,经过身份验证的用户在Confluence 服务器或数据中心实例上执行任意代码。以下产品及版本收到影响:All 4.x.x versions、All 5.x.x versions、All 6.0.x versions、All 6.1.x ver
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
Atlassian Confluence Server unspecified ~ 6.13.23 -
Atlassian Confluence Data Center unspecified ~ 6.13.23 -

II. Public POCs for CVE-2021-26084

# POC Description Source Link Shenlong Link
1 CVE-2021-26084 - Confluence Pre-Auth RCE | OGNL injection https://github.com/crowsec-edtech/CVE-2021-26084 POC Details
2 None https://github.com/alt3kx/CVE-2021-26084_PoC POC Details
3 None https://github.com/dinhbaouit/CVE-2021-26084 POC Details
4 CVE-2021-26084 Remote Code Execution on Confluence Servers, reference: https://github.com/httpvoid/writeups/blob/main/Confluence-RCE.md https://github.com/JKme/CVE-2021-26084 POC Details
5 Confluence Server Webwork OGNL injection https://github.com/h3v0x/CVE-2021-26084_Confluence POC Details
6 Atlassian Confluence Pre-Auth RCE https://github.com/Udyz/CVE-2021-26084 POC Details
7 CVE-2021-26084 - Confluence Pre-Auth RCE OGNL injection 回显 https://github.com/prettyrecon/CVE-2021-26084_Confluence POC Details
8 CVE-2021-26084 Remote Code Execution on Confluence Servers https://github.com/0xf4n9x/CVE-2021-26084 POC Details
9 Remote Code Execution on Confluence Servers : CVE-2021-26084 https://github.com/Vulnmachines/Confluence_CVE-2021-26084 POC Details
10 CVE-2021-26084 Remote Code Execution on Confluence Servers https://github.com/Osyanina/westone-CVE-2021-26084-scanner POC Details
11 批量检测 https://github.com/b1gw00d/CVE-2021-26084 POC Details
12 CVE-2021-26084 - Confluence Server Webwork OGNL injection (Pre-Auth RCE) https://github.com/taythebot/CVE-2021-26084 POC Details
13 PoC of CVE-2021-26084 written in Golang based on https://twitter.com/jas502n/status/1433044110277890057?s=20 https://github.com/bcdannyboy/CVE-2021-26084_GoPOC POC Details
14 Just run command without brain https://github.com/smallpiggy/cve-2021-26084-confluence POC Details
15 This is exploit https://github.com/maskerTUI/CVE-2021-26084 POC Details
16 This nuclei template is to verify the vulnerability without executing any commands to the target machine https://github.com/BeRserKerSec/CVE-2021-26084-Nuclei-template POC Details
17 CVE-2021-26084 https://github.com/p0nymc1/CVE-2021-26084 POC Details
18 CVE-2021-26084 Confluence OGNL injection https://github.com/Loneyers/CVE-2021-26084 POC Details
19 cve-2021-26084 EXP https://github.com/Xc1Ym/cve_2021_26084 POC Details
20 Setting up POC for CVE-2021-26084 https://github.com/wolf1892/confluence-rce-poc POC Details
21 Confluence server webwork OGNL injection https://github.com/smadi0x86/CVE-2021-26084 POC Details
22 asjhdsajdlksavksapfoka https://github.com/kkin77/CVE-2021-26084-Confluence-OGNL POC Details
23 Atlassian Confluence CVE-2021-26084 one-liner mass checker https://github.com/1ZRR4H/CVE-2021-26084 POC Details
24 A quick and dirty PoC of cve-2021-26084 as none of the existing ones worked for me. https://github.com/GlennPegden2/cve-2021-26084-confluence POC Details
25 Patched Confluence 7.12.2 (CVE-2021-26084) https://github.com/toowoxx/docker-confluence-patched POC Details
26 CVE-2021-26084 patch as provided in "Confluence Security Advisory - 2021-08-25" https://github.com/nizar0x1f/CVE-2021-26084-patch- POC Details
27 Confluence OGNL injection https://github.com/dorkerdevil/CVE-2021-26084 POC Details
28 [CVE-2021-26084] Confluence pre-auth RCE test script https://github.com/ludy-dev/CVE-2021-26084_PoC POC Details
29 None https://github.com/wdjcy/CVE-2021-26084 POC Details
30 CVE-2021-26084 - Confluence Server Webwork OGNL injection https://github.com/orangmuda/CVE-2021-26084 POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-26084

请登录查看更多情报信息。

Exploits & Public PoCs for CVE-2021-26084 (1)

Other References for CVE-2021-26084 (1)

Same Patch Batch · Atlassian · 2021-08-30 · 4 CVEs total

CVE-2021-39111 Atlassian Jira 跨站脚本漏洞
CVE-2021-39113 Atlassian Jira 代码问题漏洞
CVE-2021-39117 Atlassian Jira 跨站脚本漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2021-26084

No comments yet


Leave a comment