CVE-2022-26138criticalunder attackCWE-798

CVE-2022-26138: critical vulnerability in Atlassian Questions For Confluence

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 98%
from disclosure to weapon1 days
Published on NVDJul 20
1st PoC+1d
CISA KEV+9d
exploitation probability
98%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
6 public exploit(s)
Action required by CISAfederal deadline: 2022-08-19

Apply updates per vendor instructions.

In short

The Atlassian Questions For Confluence app creates a default user account with a hardcoded password that anyone can use to log in and access Confluence content. An attacker knowing this password can impersonate a legitimate user and view sensitive information.

Technical detail

CWE-798 hardcoded credentials vulnerability: The app creates a 'disabledsystemuser' account in the confluence-users group with a hardcoded password during installation (versions 2.7.34, 2.7.35, 3.0.2). An unauthenticated remote attacker can use these credentials to authenticate and access all resources available to the confluence-users group without authorization.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.