Junglewise Threat Intelligence

CVE-2022-26138: Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

CVE-2022-26138 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-07-29

Technologies: Atlassian Confluence Data Center, Atlassian Confluence Server. Vendors: Atlassian.

Executive brief

The Atlassian Questions For Confluence app creates a local user account with the username 'disabledsystemuser' and a hardcoded password. A remote, unauthenticated attacker with knowledge of these credentials can log into Confluence and access all content available to the confluence-users group.

Affected products

  • Atlassian Questions For Confluence 2.7.34, 2.7.35, 3.0.2
  • Atlassian Confluence Server
  • Atlassian Confluence Data Center

Timeline

  • 2022-07-20: disclosed: Initial disclosure by Atlassian and NVD publication.
  • 2022-07-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats