FAIL › dossier
Confluence Server and Data Center
PRODUCT· dossier confidence 80%
Atlassian Confluence Server and Data Center has demonstrated critical security vulnerabilities including unauthenticated RCE and path traversal flaws that were actively exploited in the wild.
PROFILE
CategorySoftware ProductWhat they doConfluence Server and Data Center is a collaboration and content management platform developed by Atlassian for enterprise teams.
SECURITY POSTURE
The product has a history of critical remote code execution vulnerabilities, including CVE-2021-26084 and CVE-2019-3398, both of which were actively exploited in the wild.
Notable failures
- CVE-2021-26084: Unauthenticated RCE via OGNL injection
- CVE-2019-3398: Privileged path traversal allowing file write
- Active exploitation of CVE-2021-26084 in the wild
Patterns: Critical RCE vulnerabilities in core components; OGNL injection vectors; Path traversal in file handling resources
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2021-26084 | critical | An unauthenticated attacker could execute code on vulnerable Atlassian Confluence servers via OGNL injection, and this vulnerability is actively exploited in the wild, often linked to ransomware attacks. |
| 2021-11-03 | CVE-2019-3398 | high | A path traversal flaw in Atlassian Confluence Server and Data Center allowed privileged remote attackers to write files and execute code. |
Open questions: Current patch status for CVE-2021-26084 and CVE-2019-3398 · Frequency of new critical vulnerabilities in recent releases
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-01 03:43:08.011385+00:00