CVE Tools

Description

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

In plain language

AI Act now

If you run Confluence Server or Confluence Data Center (and Jira Data Center) on an affected version, attackers can take over the server and run code without logging in—this is an urgent, stop-it-now situation for a typical small business.

Executive summary

CVE-2022-26134 is an unauthenticated OGNL injection leading to arbitrary code execution on Confluence Server and Confluence Data Center (via crafted requests that trigger server-side expression evaluation), and it’s listed in CISA KEV with known real-world ransomware use.

If affected, business impact
Full server takeoverRansomware riskCustomer and business data exposureService outageDamage from malicious code execution

What to do now

  1. Check your Confluence Server/Data Center (and Jira Data Center) version and whether it falls before the fixed versions (see the next steps).
  2. If your version is before 7.4.17, upgrade to 7.4.17 (Confluence Server and Confluence Data Center).
  3. If your version is 7.13.0–7.13.6, upgrade to 7.13.7.
  4. If your version is 7.14.0–7.14.2, upgrade to 7.14.3.
  5. If your version is 7.15.0–7.15.1, upgrade to 7.15.2.
  6. If your version is 7.16.0–7.16.3, upgrade to 7.16.4.
  7. If your version is 7.17.0–7.17.3, upgrade to 7.17.4.
  8. If your version is 7.18.0, upgrade to 7.18.1.
  9. If you cannot upgrade immediately, temporarily block internet access to/from the affected products, then follow the vendor advisory for compensating actions while you patch.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 2 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Jun 2, 2022
Remediation due:Jun 6, 2022
Ransomware:Known ransomware use

Required action: Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.

5 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Execution
Initial Access
View detailed technique mapping

References

and 11 more references View all →
2

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2022-26134 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows