Code Injection in Confluence Server - CVE-2021-26084
Published: September 1, 2021 / Updated: March 17, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted request, perform the OGNL injection and execute arbitrary code on the system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system but requires that the "Allow people to sign up to create their account" option is enabled.
Note, as of September 3 the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2021-26084
Links to Public Exploits and PoC-codes
- Exploit #8922 - CVE-2021-26084 (Confluence server webwork OGNL injection PoC.) (March 17, 2023)
- Exploit #8910 - CVE-2021-26084 (Confluence server webwork OGNL injection) (March 13, 2023)
- Exploit #8460 - CVE-2021-26084_Confluence (CVE-2021-26084 - Confluence Pre-Auth RCE OGNL injection 回显) (October 11, 2022)
- Exploit #7983 - Atlassian Confluence Namespace OGNL Injection (June 8, 2022)
- Exploit #7540 - CVE-2021-26084 (CVE-2021-26084 - Confluence Pre-Auth RCE | OGNL injection ) (March 27, 2022)
- Exploit #7242 - CVE-2021-26084 (POC of CVE-2021-26084, which is Atlassian Confluence Server OGNL(Object-Graph Navigation Language) Pre-Auth RCE Injection Vulneralibity.) (January 16, 2022)
- Exploit #7184 - CVE-2021-26084 (批量检测) (December 16, 2021)
- Exploit #7175 - CVE-2021-26084 (CVE-2021-26084 Remote Code Execution on Confluence Servers) (December 15, 2021)
- Exploit #7061 - Confluence Server 7.12.4 - 'OGNL injection' Remote Code Execution (RCE) (Unauthenticated) (November 25, 2021)
- Exploit #6946 - CVE-2021-26084 (CVE-2021-26084,Atlassian Confluence OGNL注入漏洞) (October 27, 2021)
- Exploit #6942 - CVE-2021-26084 (confluence远程代码执行RCE / Code By:Jun_sheng) (October 26, 2021)
- Exploit #6909 - Atlassian Confluence WebWork OGNL Injection (October 18, 2021)
- Exploit #6814 - CVE-2021-26084 () (October 3, 2021)
- Exploit #6780 - PocList (漏洞POC、EXP合集,持续更新。Apache Druid-任意文件读取(CVE-2021-36749)、ConfluenceRCE(CVE-2021-26084)、ZeroShell防火墙RCE(CVE-2019-12725)、ApacheSolr任意文件读取、蓝凌OA任意文件读取、phpStudyRCE、ShowDoc任意文件上传、原创先锋后台未授权、Kyan账号密码泄露、TerraMasterTos任意文件读取、TamronOS-IPTV系统RCE、Wayos防火墙账号密码泄露) (September 22, 2021)
- Exploit #6742 - CVE-2021-26084_Confluence (Exploit CVE 2021 26084 Confluence) (September 12, 2021)
- Exploit #6730 - docker-confluence-patched (Patched Confluence 7.12.2 (CVE-2021-26084)) (September 12, 2021)
- Exploit #6727 - CVE-2021-26084 (Confluence OGNL injection) (September 12, 2021)
- Exploit #6717 - Atlassian Confluence WebWork OGNL Injection (September 9, 2021)
- Exploit #6715 - cve-2021-26084-confluence (A quick and dirty PoC of cve-2021-26084 as none of the existing ones worked for me.) (September 7, 2021)
- Exploit #6709 - CVE-2021-26084-Confluence-OGNL (asjhdsajdlksavksapfoka) (September 6, 2021)
- Exploit #6707 - CVE-2021-26084 (CVE-2021-26084 Confluence OGNL injection) (September 5, 2021)
- Exploit #6706 - CVE-2021-26084 (Confluence OGNL Injection [CVE-2021-26084].) (September 5, 2021)
- Exploit #6704 - cve_2021_26084 (cve-2021-26084 EXP) (September 5, 2021)
- Exploit #6700 - confluence-rce-poc (Setting up POC for CVE-2021-26084) (September 5, 2021)
- Exploit #6698 - CVE-2021-26084 (CVE-2021-26084 - Confluence Pre-Auth RCE | OGNL injection ) (September 2, 2021)
- Exploit #6696 - CVE-2021-26084 (This is exploit) (September 2, 2021)
- Exploit #6695 - CVE-2021-26084 (CVE-2021-26084 - Confluence Server Webwork OGNL injection (Pre-Auth RCE)) (September 2, 2021)
- Exploit #6694 - CVE-2021-26084-Nuclei-template (This nuclei template is to verify the vulnerability without executing any commands to the target machine ) (September 2, 2021)
- Exploit #6693 - CVE-2021-26084 (CVE-2021-26084 Remote Code Execution on Confluence Servers, reference: https://github.com/httpvoid/writeups/blob/main/Confluence-RCE.md) (September 2, 2021)
- Exploit #6692 - CVE-2021-26084 (CVE-2021-26084 Remote Code Execution on Confluence Servers) (September 2, 2021)
- Exploit #6691 - CVE-2021-26084_PoC () (September 2, 2021)
- Exploit #6690 - CVE-2021-26084_GoPOC (PoC of CVE-2021-26084 written in Golang based on https://twitter.com/jas502n/status/1433044110277890057?s=20) (September 2, 2021)
- Exploit #6687 - CVE-2021-26084_Confluence (Confluence Server Webwork OGNL injection) (September 2, 2021)
- Exploit #6686 - CVE-2021-26084 () (September 2, 2021)
- Exploit #6685 - CVE-2021-26084 (批量检测) (September 2, 2021)
- Exploit #6684 - CVE-2021-26084_Confluence (CVE-2021-26084 - Confluence Pre-Auth RCE OGNL injection 命令回显+一键getshell) (September 2, 2021)
- Exploit #6683 - cve-2021-26084-confluence (Just run command without brain) (September 2, 2021)
- Exploit #6681 - CVE-2021-26084 (Atlassian Confluence Pre-Auth RCE) (September 2, 2021)
- Exploit #6680 - Confluence_CVE-2021-26084 (Remote Code Execution on Confluence Servers : CVE-2021-26084) (September 1, 2021)