Junglewise Threat Intelligence

CVE-2022-26134: Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

CVE-2022-26134 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-06-02

Technologies: Atlassian Confluence Data Center, Atlassian Data Center, Atlassian Confluence Server. Vendors: Atlassian.

Executive brief

An OGNL injection vulnerability in Atlassian Confluence Server and Data Center allows an unauthenticated remote attacker to execute arbitrary code. The flaw stems from improper neutralization of special elements used in expression language statements.

Affected products

  • Atlassian Confluence Server from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1
  • Atlassian Confluence Data Center from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1

Timeline

  • 2022-06-02: disclosed: Initial security advisory published by Atlassian
  • 2022-06-02: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-02: exploited: Reported as being exploited in the wild at the time of disclosure

Related threats