{"id":"CVE-2021-26084","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-26084","summary":"In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence…","details":"In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.","published":"2021-08-30T07:15:06.587","modified":"2026-06-17T03:42:49.750","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.99999,"percentile":0.99993,"asOf":"2026-08-28"},"cisaKev":{"dateAdded":"2021-11-03","dueDate":"2021-11-17","knownRansomwareCampaignUse":true},"exploitsKnown":59,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGNL-Injection.html"},{"type":"FIX","url":"https://jira.atlassian.com/browse/CONFSERVER-67940"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGNL-Injection.html"},{"type":"FIX","url":"https://jira.atlassian.com/browse/CONFSERVER-67940"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26084"}],"provenance":{"sources":["OSV.dev","NVD","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T03:42:49.750"}}