Is CVE-2021-26084 patched on Confluence?

/static/assets/linux-logo.svg
Confluence Server and Data Center are vulnerable to an OGNL injection vulnerability that allows an unauthenticated attacker to execute arbitrary code. This TTP attempts to execute code on the Confluence server by using curl to make a specially crafted POST request. This exploit is trivial to use, reliable, and affects most versions of Confluence Server.
locked
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.

Login

Test this TTP

Download Operator (1.7.1)
Test this TTP using one of our Operator chains
Is CVE-2021-26084 patched on Confluence?

2022-08-02

/static/assets/linux-logo.svg
A TTP that exploits CVE-2021-26084 in Confluence Server