CRITICAL

CVE-2022-26138

Atlassian Questions For Confluence 2022-07-20 CVSS v3.1
CVSS
9.8
KEV

Description

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

Summary dbcve.org

The Atlassian Questions For Confluence app (versions 2.7.34, 2.7.35, and 3.0.2) provisions a Confluence user account named 'disabledsystemuser' in the confluence-users group with a hardcoded password at install time. A remote, unauthenticated attacker who knows or obtains this hardcoded credential can authenticate to Confluence and read all content accessible to any user in the confluence-users group.

Mitigation

Upgrade the Questions For Confluence app to a fixed version, remove the 'disabledsystemuser' account from Confluence, and audit access logs for any prior authentication or activity performed by that account to determine if data was exposed.

Patch Commit

Weakness (CWE)

CWE-798 Hard-coded Credentials

EPSS Score

98.17%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE