LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-26084: Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-26084 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.

CVE-2021-26084 is an Object-Graph Navigation Language (OGNL) injection vulnerability in Atlassian Confluence Server and Data Center. An unauthenticated attacker may be able to execute code on a vulnerable instance. CISA notes known ransomware use, so organizations running Confluence should treat this as high priority and confirm exact impact and fixed releases against the vendor advisory.

This guidance is for IT and security teams who need to inventory, detect, and remediate the issue without relying on unverified technical claims.

How it works

The weakness is classified as CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement. In products that evaluate OGNL expressions, user-controlled input that reaches an expression evaluator without proper neutralization can be interpreted as executable expression logic rather than inert data.

In this class of flaw, an attacker who can submit crafted input to an exposed Confluence endpoint may cause the server to evaluate malicious OGNL. Successful abuse can lead to arbitrary code execution in the context of the Confluence process. The CISA summary states that exploitation may be possible without authentication. Exact request paths, parameters, and preconditions are not repeated here; defenders must obtain those details only from the official Atlassian advisory and their own testing in a controlled environment.

Am I affected? How to find it in your systems

Confluence Server and Data Center typically run as on-premises or self-managed collaboration platforms, often behind reverse proxies or load balancers, and are commonly integrated with identity providers and file stores. Cloud-hosted Atlassian offerings are outside the scope of this CVE description unless the vendor advisory says otherwise.

How to remediate

Patch first. Apply the updates Atlassian specifies for CVE-2021-26084, following the vendor’s installation and restart procedures. CISA’s required action is to apply updates per vendor instructions. After patching, verify the running version and re-test exposure.

If you can't patch immediately

Use compensating controls only as a bridge until the vendor update is applied.

If your data may have been exposed

Actively exploited vulnerabilities with known ransomware use can lead to full compromise of the Confluence host, theft of content and credentials, and lateral movement. If you suspect exploitation, isolate affected systems, preserve logs and disk evidence, rotate secrets that Confluence could access, and follow your incident response plan, including notification obligations.

You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora, then enforce password resets and MFA where relevant.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAtlassian · Confluence Server and Data Center
WeaknessCWE-917
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities