CRITICAL

CVE-2022-26134

Atlassian Confluence Data Center 2022-06-03 CVSS v3.1
CVSS
9.8
KEV

Description

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

Summary dbcve.org

An OGNL (Object-Graph Navigation Language) injection vulnerability in affected versions of Confluence Server and Data Center allows an unauthenticated remote attacker to execute arbitrary code on the underlying server. Exploitation requires no credentials and is reachable over the network, making it critical for any internet-exposed or untrusted-network Confluence instance.

Mitigation

Upgrade Confluence Server and Data Center to a fixed version per Atlassian's advisory: 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, or 7.18.1 (or later), and verify no indicators of prior compromise are present.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-917

EPSS Score

100%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE