CVE-2019-3398PoC(atlassian / confluence_server)

LOWCVSS 8.8 · HIGHCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch atlassian confluence_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability.

2.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • confluence_server

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
confluence_server

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-25: 1PoC Mentioned / Linked · 2026-08-25: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-25: 108-25
Signal classification1 categories
PoC
1100.0%
Full discourse1 post
  • Vulnerability Research Labs@vulnresearchlab
    PoC

    A path traversal in Atlassian Confluence allowed for arbitrary file write and remote code execution. We reproduced the public exploit for CVE-2019-3398 and confirmed the vendor patch closes it. Compute cost for the run was $0.71.

    Post summary

    The post confirms a path traversal CVE-2019-3398 in Atlassian Confluence, reproduces the public PoC, and verifies that the vendor patch effectively mitigates the vulnerability.

    0001054
    8 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appatlassianconfluence_server---

Explore more