CyberSec.Space Logo
Back to CVE Browser

CVE-2022-26134

πŸ”₯ Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2022-06-03
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

Affected Platforms (CPE)

πŸ“¦
Atlassian

Confluence Data Center

>= 1.3 and < 7.4.17>= 7.13.0 and < 7.13.7>= 7.14.0 and < 7.14.3>= 7.15.0 and < 7.15.2>= 7.16.0 and < 7.16.4>= 7.17.0 and < 7.17.4= 7.18.0
πŸ“¦
Atlassian

Confluence Server

>= 1.3 and < 7.4.17>= 7.13.0 and < 7.13.7>= 7.14.0 and < 7.14.3>= 7.15.0 and < 7.15.2>= 7.16.0 and < 7.16.4>= 7.17.0 and < 7.17.4= 7.18.0

References & Advisories

Related Vulnerabilities