Skip to content
COOEY

FAIL › dossier

Atlassian

VENDOR

· dossier confidence 60%

Atlassian is a major collaboration software vendor with a severe and recurring security posture marked by critical RCE vulnerabilities in its flagship products like Confluence and Jira. The company has a history of shipping products with unpatched critical flaws, including OGNL injection, template injection, and command injection, requiring emergency patches and exposing organizations to significant risk.

PROFILE
Categorycollaboration software vendorWhat they doAtlassian provides collaboration software enabling organizations to connect teams through a system of work that unlocks productivity at scale worldwide. Its product portfolio includes Jira, a project management platform, and Confluence, a connected workspace.Founded2002HQSydney, Australia Websitehttps://www.atlassian.com ↗
SECURITY POSTURE

Atlassian has a poor security track record characterized by a high frequency of critical remote code execution (RCE) vulnerabilities across its core products, including Confluence, Jira, and Bitbucket. The company has repeatedly shipped products with unpatched critical flaws, including OGNL injection, server-side template injection, and command injection, often requiring emergency patches.

Notable failures
  • CVE-2022-26134: Critical unauthenticated RCE in Confluence Server/Data Center
  • CVE-2021-26084: Critical OGNL injection RCE in Confluence Server/Data Center
  • CVE-2023-22515: Critical broken access control allowing unauthorized admin account creation in Confluence
  • CVE-2022-36804: High command injection in Bitbucket Server/Data Center API endpoints
  • CVE-2021-26085: Critical pre-authorization arbitrary file read in Confluence Server
  • CVE-2022-26138: High hard-coded credentials in Questions For Confluence App
Patterns: repeated critical RCE vulnerabilities in core collaboration products; unpatched OGNL and server-side template injection flaws; broken access control and authorization flaws allowing privilege escalation; hard-coded credentials and improper authorization in third-party or internal apps
FAILURE HISTORY · 13
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2021-26084 critical An unauthenticated attacker could execute code on vulnerable Atlassian Confluence servers via OGNL injection, and this vulnerability is actively exploited in the wild, often linked to ransomware attacks.
2021-11-03 CVE-2019-3396 critical Atlassian Confluence Server and Data Center had a server-side template injection vulnerability actively exploited by ransomware actors, enabling remote code execution.
2022-09-30 CVE-2022-36804 high Bitbucket Server and Data Center exposed to command injection attacks via multiple API endpoints
2024-01-24 CVE-2023-22527 critical Unauthenticated OGNL template injection in Atlassian Confluence Data Center and Server allows remote code execution.
2023-11-07 CVE-2023-22518 critical An unauthenticated attacker could exploit an improper authorization flaw in Atlassian Confluence Data Center and Server to cause significant data loss.
2023-10-05 CVE-2023-22515 critical Atlassian Confluence Data Center and Server suffered a broken access control flaw allowing attackers to create unauthorized admin accounts and access the system.
2022-06-02 CVE-2022-26134 critical An unauthenticated remote code execution flaw in Atlassian Confluence Server/Data Center was actively exploited in the wild and linked to ransomware attacks.
2022-03-28 CVE-2021-26085 critical Atlassian Confluence Server had a pre-auth file read vulnerability actively exploited by ransomware actors, allowing unauthorized access to restricted files.
2021-11-03 CVE-2019-3398 high A path traversal flaw in Atlassian Confluence Server and Data Center allowed privileged remote attackers to write files and execute code.
2021-11-03 CVE-2019-11580 critical Atlassian's Crowd product shipped with a development plugin enabled, leading to remote code execution vulnerability actively exploited by ransomware actors.
2022-03-07 CVE-2019-11581 high Atlassian Jira Server and Data Center suffered a server-side template injection vulnerability allowing remote code execution.
2022-07-29 CVE-2022-26138 high An Atlassian Confluence app shipped with hardcoded credentials, allowing unauthorized access to Confluence data and functionality.
2024-11-12 CVE-2021-26086 high Atlassian Jira Server/Data Center suffered a remote path traversal vulnerability (CVE-2021-26086) allowing file read access to /WEB-INF/web.xml.
SENTIMENT · TRUSTED SOURCES
synthesisnegative-0.60
Acknowledged vulnerability, but no explicit condemnation.
synthesissevere-fallout-0.70
Significant negative impact due to active exploitation and inclusion in KEV lists.
synthesisnegative-0.70
synthesissevere-fallout-0.70
Widespread exploitation and CISA inclusion indicate a serious failure with significant fallout.
www.cvefind.com ↗severe-fallout-0.60
Neutral description of CVE data, no judgment.
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
app.opencve.io ↗severe-fallout-0.50
Brief mention, no specific judgment.
"The Essential Addons for Elementor plugin is vulnerable to Stored Cross-Site Scripting..."
CISA ↗severe-fallout-0.80
CISA's inclusion confirms active exploitation, a serious failure.
"CISA Adds Three Known Exploited Vulnerabilities to Catalog"
xposedornot.com ↗severe-fallout-0.60
Mentioned in a list of breaches, no specific judgment.
"7-Eleven (2026, 281.3K records)"
cooey ↗severe-fallout-0.60
Neutral reporting of the vulnerability.
"Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution."
cvefeed.io ↗severe-fallout-0.90
Strongly negative due to KEV listing indicating active exploitation.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is one of the highest-signal inputs for risk-based patch mana"
www.cvefind.com ↗severe-fallout-0.40
Neutral, simply lists the vulnerability in a database.
xposedornot.com ↗severe-fallout+0.00
Neutral, simply lists the vulnerability in a breach directory.
app.opencve.io ↗severe-fallout-0.30
Neutral, describes the vulnerability in a list of CVEs.
cybersecuritynews.com ↗severe-fallout-0.80
Negative, highlights active exploitation and potential for severe consequences.
"Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution, install persistent web shells, and steal cryptographic keys from exposed systems."
cvedb.shodan.io ↗severe-fallout-0.50
Neutral, lists the vulnerability in a database.
cooey ↗negative-0.60
Technical description, no judgment.
"Atlassian Confluence Server and Data Center contain a path traversal vulnerability."
cooey ↗negative-1.00
severe-fallout
"…"
cooey ↗severe-fallout-0.80
Initial reporting focused on the vulnerability itself.
"Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code."
cybersecuritynews.com ↗severe-fallout+0.00
Brief mention in a broader context of vulnerabilities, no specific judgment.
"Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution..."
cvefeed.io ↗severe-fallout-0.90
Explicitly flagged as actively exploited, a severe indicator.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
Open questions: Atlassian's current patch SLA and vulnerability disclosure policy · Whether Atlassian has implemented any architectural changes to mitigate OGNL/template injection risks
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-16 05:01:08.310214+00:00