cbcvebase.
CVE-2021-26084
published 2021-08-30

CVE-2021-26084: In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
100.00%
100.0th percentile
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

Affected

22 ranges
VendorProductVersion rangeFixed in
atlassianconfluence_data_center< 6.13.236.13.23
atlassianconfluence_data_center>= 6.14.0 < unspecifiedunspecified
atlassianconfluence_data_center>= 6.14.0 < 7.4.117.4.11
atlassianconfluence_data_center>= 7.12.0 < unspecifiedunspecified
atlassianconfluence_data_center>= 7.12.0 < 7.12.57.12.5
atlassianconfluence_data_center>= 7.5.0 < unspecifiedunspecified
atlassianconfluence_data_center>= 7.5.0 < 7.11.67.11.6
atlassianconfluence_data_center>= unspecified < 6.13.236.13.23
atlassianconfluence_data_center>= unspecified < 7.4.117.4.11
atlassianconfluence_data_center>= unspecified < 7.11.67.11.6
atlassianconfluence_data_center>= unspecified < 7.12.57.12.5
atlassianconfluence_server< 6.13.236.13.23
atlassianconfluence_server>= 6.14.0 < unspecifiedunspecified
atlassianconfluence_server>= 6.14.0 < 7.4.117.4.11
atlassianconfluence_server>= 7.12.0 < unspecifiedunspecified
atlassianconfluence_server>= 7.12.0 < 7.12.57.12.5
atlassianconfluence_server>= 7.5.0 < unspecifiedunspecified
atlassianconfluence_server>= 7.5.0 < 7.11.67.11.6
atlassianconfluence_server>= unspecified < 6.13.236.13.23
atlassianconfluence_server>= unspecified < 7.4.117.4.11
atlassianconfluence_server>= unspecified < 7.11.67.11.6
atlassianconfluence_server>= unspecified < 7.12.57.12.5

Detection & IOCsextracted from sources · hover to see the quote

ip188.166.137.241
urlhttp://188.166.137.241/wp-content/themes/twentyseventeen/dk86
ip153.121.58.102
urlhttp://153.121.58.102:80/wp-content/themes/zuki/m8
ip3.10.224.87
urlhttp://3.10.224.87/.a/dk86
hash0e574fd30e806fe4298b3cbccb8d1089454f42f52892f87554325cb352646049
hash3dbcd99edb3422b8fdc458b82aa7ecfe31296d32bb4d54450c9e9cac29fb6141
hasha254a26a27e36de4d96b6023f2dc8a82c4c4160a1d72b822f34ffdd5e9a0e0c9
hash61879d5b2f083b69e8e6cc6afce00be6619176151b093de14f2778a87ea46565
hash6e25ad03103a1a972b78c642bac09060fa79c460011dc5748cbb433cc459938b
hashdd603db3e2c0800d5eaa262b6b8553c68deaa486b545d4965df5dc43217cc839
ip194.38.20.199
urlhttp://194.38.20.199/wb.sh
urlhttp://194.38.20.199/kinsing
filenamepty86
filename.kswapd
filenamekdevtmpfsi
ip209.141.40.190
urlhttp://209.141.40.190/oracleservice.exe
urlhttp://209.141.40.190/wxm.exe
ip27.1.1.34
urlhttp://27.1.1.34:8080/docs/s/config.json
urlhttp://27.1.1.34:8080/examples/clean.bat
urlhttp://27.1.1.34:8080/docs/s/sys.ps1
ip222.122.47.27
urlhttp://222.122.47.27:2143/auth/xmrig.exe
urlhttp://pastebin.com/raw/bcFqDdXx
urlhttp://pastebin.com/raw/g93wWHkR
ip164.52.212.196
urlhttp://164.52.212.196:88/eth.jpg
urlhttp://164.52.212.196:88/1.jpg
ip66.42.117.168
urlhttp://66.42.117.168/BootCore_jsp
urlhttp://209.141.40.190/xms
ip172.96.249.219
urlhttp://172.96.249.219:88/.jpg
urlhttp://172.96.249.219:88/1.jpg
domainzgpay.cc
urlhttps://zgpay.cc/css/kwork.sh
urlhttps://raw.githubusercontent.com/alreadyhave/thinkabout/main/kwork.sh
ip213.152.165.29
urlhttp://213.152.165.29/vmicguestvs.dll
urlhttp://213.152.165.29/uninstall.bat
urlhttp://213.152.165.29/x.bat
otherSnort SID 58093
otherSnort SID 58094
otherTrend Micro IPS rule 1011117 - Atlassian Confluence Server RCE vulnerability CVE-2021-26084
  • Monitor for presence of malicious filenames 'kdevtmpfsi' and 'kinsing' on Linux hosts — these are hallmark indicators of the Kinsing cryptomining campaign exploiting CVE-2021-26084
  • Detect hidden file '.kswapd' on Linux systems — used by the Muhstik botnet campaign post-exploitation of CVE-2021-26084 for cryptomining
  • Alert on scheduled task creation named '.NET Framework NGEN v4.0.30319 32' — used by z0Miner to persist and download scripts from Pastebin every five minutes after exploiting CVE-2021-26084
  • Detect outbound HTTP connections to Pastebin raw URLs (pastebin.com/raw/*) from Confluence server processes — indicative of z0Miner C2 staging activity post-exploitation
  • Apply Trend Micro IPS rule 1005934 'Identified Suspicious Command Injection Attack' alongside rule 1011117 for broader OGNL injection detection coverage on Confluence
  • CVE-2021-26084 is an OGNL injection in Confluence Server/Data Center exploitable by unauthenticated attackers; monitor Confluence web request logs for OGNL expression syntax in POST body parameters targeting the /pages/doenterpagevariables.action or similar Webwork endpoints
  • ·The Pastebin URLs used by z0Miner for C2 staging were already taken down at time of reporting; IOC may no longer be active but the pattern of Pastebin-hosted payloads should still be monitored
  • ·Trend Micro IPS rule 1011117 ships in prevent mode by default and is included in the recommendation scan — verify this is active and not in detect-only mode on Confluence deployments

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.