CyberSec.Space Logo
CVEブラウザに戻る

CVE-2022-26138

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2022-07-20
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

Affected Platforms (CPE)

📦
Atlassian

Questions For Confluence

= 2.7.34= 2.7.35= 3.0.2

References & Advisories

関連する脆弱性情報