PromptRiskDBThreat intelligence atlas

CVE-2022-26138 - Atlassian Confluence

AI Vulnerability Context

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account...

Overview

A source-backed snapshot of this vulnerability.

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEVCRITICAL
CVE ID
CVE-2022-26138
Vendor/project
Atlassian
Product
Confluence
Vulnerability name
Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
Date added
2022-07-29
Due date
2022-08-19
Known ransomware campaign use
Unknown
CVSS v3
9.8
CWE-798

Exploit context

What the vulnerability is about.

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

Source evidence

Original public records and references for this page.

Original source

Original source links

Open the public records and source datasets used for this page.