CVE-2022-26134
Description
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.
In plain language
AI Act nowIf you run Confluence Server or Confluence Data Center (and Jira Data Center) on an affected version, attackers can take over the server and run code without logging in—this is an urgent, stop-it-now situation for a typical small business.
CVE-2022-26134 is an unauthenticated OGNL injection leading to arbitrary code execution on Confluence Server and Confluence Data Center (via crafted requests that trigger server-side expression evaluation), and it’s listed in CISA KEV with known real-world ransomware use.
What to do now
- Check your Confluence Server/Data Center (and Jira Data Center) version and whether it falls before the fixed versions (see the next steps).
- If your version is before 7.4.17, upgrade to 7.4.17 (Confluence Server and Confluence Data Center).
- If your version is 7.13.0–7.13.6, upgrade to 7.13.7.
- If your version is 7.14.0–7.14.2, upgrade to 7.14.3.
- If your version is 7.15.0–7.15.1, upgrade to 7.15.2.
- If your version is 7.16.0–7.16.3, upgrade to 7.16.4.
- If your version is 7.17.0–7.17.3, upgrade to 7.17.4.
- If your version is 7.18.0, upgrade to 7.18.1.
- If you cannot upgrade immediately, temporarily block internet access to/from the affected products, then follow the vendor advisory for compensating actions while you patch.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2022-26134 and every CVE in our database. Create a free account — no credit card required.
Create Free Account