CVE-2022-26138
published 2022-07-20CVE-2022-26138: The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the…
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-08-19
Exploited in the wild
EPSS
98.17%
99.9th percentile
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | questions_for_confluence | — | — |
| atlassian | questions_for_confluence | — | — |
| atlassian | questions_for_confluence | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation by checking for the presence of the hardcoded account 'disabledsystemuser' in the confluence-users group; its existence indicates the vulnerable app version was installed. ↗
- →Verify exploitation by navigating to the Confluence user profile page after authenticating with the hardcoded credentials; a 302 Location header alone is insufficient and may produce false positives. ↗
- →Check the active user list for the 'disabledsystemuser' account even after uninstalling the Questions for Confluence app, as the account persists post-uninstall. ↗
- ·The hardcoded account is only created when specific vulnerable versions of the Questions for Confluence app are installed (2.7.34, 2.7.35, 3.0.2); other versions are not affected. ↗
- ·Atlassian Cloud (atlassian.net-hosted) instances are not affected; only on-premises Confluence Server and Data Center deployments are vulnerable. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-23xf-wg9r-49fr: The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with
ghsa_unreviewed·2022-07-21
CVE-2022-26138 [CRITICAL] CWE-798 GHSA-23xf-wg9r-49fr: The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.
VulnCheck
Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
vulncheck·2022·CVSS 9.8
CVE-2022-26138 [CRITICAL] CWE-798 Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group.
Affected: Atlassian Confluence Server and Data Center
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://go.recordedfuture.com/hubfs/reports/ta-2023-0302.pdf; https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2023/11/09055246/Modern-Asian-APT-groups-TTPs_report_eng.pdf;
CISA
Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
cisa·2022-07-29·CVSS 9.8
CVE-2022-26138 [CRITICAL] CWE-798 Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
Vulnerability: Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
Affected: Atlassian Confluence
Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group.
Required Action: Apply updates per vendor instructions.
Notes: https://confluence.atlassian.com/doc/questions-for-confluence-security-advisory-2022-07-20-1142446709.html; https://nvd.nist.gov/vuln/detail/CVE-2022-26138
Remediation Due Date: 2022-08-19
No detection rules found.
Nuclei
Atlassian Questions For Confluence - Hardcoded Credentials
nuclei·CVSS 9.8
CVE-2022-26138 [CRITICAL] Atlassian Questions For Confluence - Hardcoded Credentials
Atlassian Questions For Confluence - Hardcoded Credentials
Atlassian Questions For Confluence contains a hardcoded credentials vulnerability. When installing versions 2.7.34, 2.7.35, and 3.0.2, a Confluence user account is created in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password can exploit this vulnerability to log into Confluence and access all content accessible to users in the confluence-users group.
Template:
id: CVE-2022-26138
info:
name: Atlassian Questions For Confluence - Hardcoded Credentials
author: HTTPVoid
severity: critical
description: |
Atlassian Questions For Confluence contains a hardcoded credentials vulnerability. When installing versions 2.7.34, 2
Tenable
Cybersecurity Snapshot: Russia-backed Hackers Aim at Critical Infrastructure Orgs, as Crypto Fraud Balloons
blogs_tenable·2024-09-13
Cybersecurity Snapshot: Russia-backed Hackers Aim at Critical Infrastructure Orgs, as Crypto Fraud Balloons
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
CISA, FBI urge admins to patch Atlassian Confluence immediately
blogs_bleepingcomputer·2023-10-16·CVSS 9.8
CVE-2023-22515 [CRITICAL] CISA, FBI urge admins to patch Atlassian Confluence immediately
## CISA, FBI urge admins to patch Atlassian Confluence immediately
## Sergiu Gatlan
CISA, FBI, and MS-ISAC warned network admins today to immediately patch their Atlassian Confluence servers against a maximum severity flaw actively exploited in attacks.
Tracked as CVE-2023-22515 , this critical privilege escalation flaw affects Confluence Data Center and Server 8.0.0 and later and is remotely exploitable in low-complexity attacks that don't require user interaction.
On October 4, when it released security updates, Atlassian advised customers to upgrade their Confluence instances as soon as possible to one of the fixed versions (i.e., 8.3.3 or later, 8.4.3 or later, 8.5.2 or later) as the bug was already exploited in the wild as a zero-day.
Those who couldn't upgrade were urged to shut
Bleepingcomputer
Atlassian patches critical Confluence zero-day exploited in attacks
blogs_bleepingcomputer·2023-10-04·CVSS 9.8
[CRITICAL] Atlassian patches critical Confluence zero-day exploited in attacks
## Atlassian patches critical Confluence zero-day exploited in attacks
## Sergiu Gatlan
Australian software company Atlassian released emergency security updates to fix a maximum severity zero-day vulnerability in its Confluence Data Center and Server software, which has been exploited in attacks.
"Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances," the company said .
"Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is no
Qualys
Introducing Qualys Threat Research Thursdays | Qualys
blogs_qualys·2022-09-01
Introducing Qualys Threat Research Thursdays | Qualys
#### Table of Contents
- Threat Intelligence from the Qualys Blog
- New Threat Hunting Tools & Techniques
- New Vulnerabilities
- Introducing the Monthly Threat Thursdays Webinar
Welcome to the first edition of the Qualys Research Team’s “Threat Research Thursday” where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. We will endeavor to issue these update reports regularly, as often as every other week, or as our threat intelligence output warrants.
## Threat Intelligence from the Qualys Blog
Here is a roundup of the most interesting blogs from the Qualys Research Team from the past couple of weeks:
- New Qualys Research Report: Evolution of Quasar RAT – This free downloadable report gives a sneak pee
Qualys
Atlassian Confluence: Questions for Confluence App Hardcoded Credentials Vulnerability (CVE-2022-26138) | Qualys
blogs_qualys·2022-08-17·CVSS 9.8
CVE-2022-26138 [CRITICAL] Atlassian Confluence: Questions for Confluence App Hardcoded Credentials Vulnerability (CVE-2022-26138) | Qualys
#### Table of Contents
- About CVE-2022-26138
- Hardcoded Credentials Vulnerability
- Detecting the Vulnerability with Qualys Web Application Scanning
- Qualys WAS Report
- Solution & Mitigation
- Credit
- CVE Details:
Over the last few months, Atlassian Confluence has increasingly become a target for attackers. In June 2022, a critical severity OGNL Remote Code Execution vulnerability was disclosed (CVE-2022-26134). More recently, CVE-2022-26138 was disclosed on social media platforms in July 2022.
In CVE-2022-26138, a Confluence user account is created by the Questions for Confluence app with hardcoded credentials stored inside the plugin jar file available on Atlassian packages. An attacker with knowledge of these credentials could log into the Confluence application and access all c
Qualys
Atlassian Confluence: Questions for Confluence App Hardcoded Credentials Vulnerability (CVE-2022-26138)
blogs_qualys·2022-08-17·CVSS 9.8
CVE-2022-26138 [CRITICAL] Atlassian Confluence: Questions for Confluence App Hardcoded Credentials Vulnerability (CVE-2022-26138)
## Table of Contents
About CVE-2022-26138
Hardcoded Credentials Vulnerability
Detecting the Vulnerability with Qualys Web Application Scanning
Qualys WAS Report
Solution & Mitigation
Credit
CVE Details:
Over the last few months, Atlassian Confluence has increasingly become a target for attackers. In June 2022, a critical severity OGNL Remote Code Execution vulnerability was disclosed (CVE-2022-26134). More recently, CVE-2022-26138 was disclosed on social media platforms in July 2022.
In CVE-2022-26138, a Confluence user account is created by the Questions for Confluence app with hardcoded credentials stored inside the plugin jar file available on Atlassian packages . An attacker with knowledge of these credentials could log into the Confluence application and access all contents w
Qualys
August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical. | Qualys
blogs_qualys·2022-08-09·CVSS 6.5
[MEDIUM] August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The August 2022 Microsoft Vulnerabilities Are Classified As Follows:
- Notable Microsoft Vulnerabilities Patched
- Security Feature Bypass Vulnerabilities Addressed
- Microsoft Critical and Important Vulnerability Highlights
- Microsoft Edge | Last But Not Least
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Qualys Threat Protection High-Rated Advisories for August 1-9, 2022
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response With Patch Management (PM)
- Evaluate Vendor-Suggested Workarounds With Policy Compliance
- Patch Tuesday is Complete.
- Qualys Monthly Webinar Series
- Join the Webinar This Month in Vulnerabilities & Patches
## Microsoft
Qualys
August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical.
blogs_qualys·2022-08-09·CVSS 6.5
[MEDIUM] August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
The August 2022 Microsoft Vulnerabilities Are Classified As Follows:
Notable Microsoft Vulnerabilities Patched
Security Feature Bypass Vulnerabilities Addressed
Microsoft Critical and Important Vulnerability Highlights
Microsoft Edge | Last But Not Least
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Qualys Threat Protection High-Rated Advisories for August 1-9, 2022
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response With Patch Management (PM)
Evaluate Vendor-Suggested Workarounds With Policy Compliance
Patch Tuesday is Complete.
Qualys Monthly Webinar Series
Join the Webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Sum
Talos
Threat Source newsletter (Aug. 4, 2022) — BlackHat 2022 preview
blogs_talos·2022-08-04
Threat Source newsletter (Aug. 4, 2022) — BlackHat 2022 preview
## Threat Source newsletter (Aug. 4, 2022) — BlackHat 2022 preview
Welcome to this week’s edition of the Threat Source newsletter.
After what seems like forever and honestly has been a really long time, we’re heading back to BlackHat in-person this year. We’re excited to see a lot of old friends again to commiserate, hang out, trade stories and generally talk about security.
Throughout the two days of the main conference, we’ll have a full suite of flash talks at the Cisco Secure booth and several sponsored talks. Since this is the last edition of the newsletter before BlackHat starts, it’s probably worthwhile running through all the cool stuff we’ll have going on at Hacker Summer Camp.
Our booth should be easy enough to find — it’s right by the main entrance to Bayside B. If you get t
Talos
Threat Source newsletter (Aug. 4, 2022) — BlackHat 2022 preview
blogs_talos·2022-08-04
Threat Source newsletter (Aug. 4, 2022) — BlackHat 2022 preview
Welcome to this week’s edition of the Threat Source newsletter.
After what seems like forever and honestly has been a really long time, we’re heading back to BlackHat in-person this year. We’re excited to see a lot of old friends again to commiserate, hang out, trade stories and generally talk about security.
Throughout the two days of the main conference, we’ll have a full suite of flash talks at the Cisco Secure booth and several sponsored talks. Since this is the last edition of the newsletter before BlackHat starts, it’s probably worthwhile running through all the cool stuff we’ll have going on at Hacker Summer Camp.
Our booth should be easy enough to find — it’s right by the main entrance to Bayside B. If you get to the Trellix Lounge, you’ve gone too far north. Our researchers wil
Checkpoint
1st August – Threat Intelligence Report
blogs_checkpoint·2022-08-01·CVSS 7.8
CVE-2022-22047 [HIGH] 1st August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 1st August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 1st August, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The LockBit Ransomware gang has claimed the attack on Italy’s tax agency, the Internal Revenue Service. According to LockBit’s message on their dark web site, the group stole 100 GB of sensitive data, including financial reports, contracts and other documents that they threaten to leak online if the victim does not pay the ra
Recorded Future
Analyze Recent Atlassian Vulnerabilities and Keep Your Infrastructure Protected
blogs_recorded_future·CVSS 9.6
[CRITICAL] Analyze Recent Atlassian Vulnerabilities and Keep Your Infrastructure Protected
## Analyze Recent Atlassian Vulnerabilities and Keep Your Infrastructure Protected
For years, software solutions built by Atlassian have found their way to nearly every organization's software stack. Tools such as JIRA, Confluence, Bamboo, and BitBucket are often seen playing a crucial role in various departments across enterprises.
From managing projects or handling organization-wide documentation, to hosting the very code of a product being developed by the organization, the constant reliance upon and amount of historical data held within these applications have turned them into a lucrative target for attackers, expanding the attack surface in the process.
## Historical Atlassian Vulnerabilities
Traditionally, vulnerabilities within the Atlassian software stack have originated from d
Recorded Future
Analyze Recent Atlassian Vulnerabilities and Keep Your Infrastructure Protected
blogs_recorded_future·CVSS 9.6
[CRITICAL] Analyze Recent Atlassian Vulnerabilities and Keep Your Infrastructure Protected
# Analyze Recent Atlassian Vulnerabilities and Keep Your Infrastructure Protected
For years, software solutions built by Atlassian have found their way to nearly every organization's software stack. Tools such as JIRA, Confluence, Bamboo, and BitBucket are often seen playing a crucial role in various departments across enterprises.
From managing projects or handling organization-wide documentation, to hosting the very code of a product being developed by the organization, the constant reliance upon and amount of historical data held within these applications have turned them into a lucrative target for attackers, expanding the attack surface in the process.
## Historical Atlassian Vulnerabilities
Traditionally, vulnerabilities within the Atlassian software stack have originated from di
Greynoiseio
Spike in Atlassian Exploitation Attempts: Patching is Crucial
blogs_greynoiseio
Spike in Atlassian Exploitation Attempts: Patching is Crucial
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
https://confluence.atlassian.com/doc/confluence-security-advisory-2022-07-20-1142446709.htmlhttps://jira.atlassian.com/browse/CONFSERVER-79483https://confluence.atlassian.com/doc/confluence-security-advisory-2022-07-20-1142446709.htmlhttps://jira.atlassian.com/browse/CONFSERVER-79483https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26138
2022-07-20
Published
2022-07-29
Added to CISA KEV
Exploited in the wild