Executive brief
A broken access control vulnerability in Atlassian Confluence Data Center and Server allows unauthenticated remote attackers to create unauthorized administrator accounts. This flaw enables full access to affected Confluence instances, though Atlassian Cloud sites are not impacted.
Affected products
- Atlassian Confluence Data Center
- Atlassian Confluence Server
Timeline
- 2023-10-05: disclosed
- 2023-10-05: advisory
- 2023-10-05: exploited: Added to CISA KEV catalog on this date.
- 2023-10-05: kev added