Remote code execution vulnerability present in certain versions of Atlassian Confluence

Australian Cyber Security Centre

Background /What has happened?

A vulnerability (CVE-2021-26084) has been identified in certain self-hosted versions of Atlassian Confluence which can allow a remote malicious cyber actor to execute arbitrary code which could enable the actor to gain full control of a vulnerable server. Atlassian has identified that in some instances this vulnerability is able to be exploited by an unauthenticated user. The ACSC is aware of scanning and attempted exploitation of this vulnerability.

Atlassian has identified that this vulnerability does not affect Confluence Cloud customers.

/Public Release. View in full here.