All verified exploits

CVE-2021-26085 Path Traversal via Static Resources

Deterministic critical Confluence CISA KEV Added cve-verified-cve-2021-26085

Reads internal configuration files through Confluence's semicolon path parameter bypass, the same technique as the Jira variant.

Is your app exploitable through CVE-2021-26085?

Scan your domain free