cbcvebase.
CVE-2022-26138
published 2022-07-20

CVE-2022-26138: The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-08-19
Exploited in the wild
EPSS
98.17%
99.9th percentile
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

Affected

3 ranges
VendorProductVersion rangeFixed in
atlassianquestions_for_confluence
atlassianquestions_for_confluence
atlassianquestions_for_confluence

Detection & IOCsextracted from sources · hover to see the quote

otherdisabledsystemuser
otherdisabled1system1user6708
pathdefault.properties
filenameconfluence-questions-X.X.X.jar
  • Detect exploitation by checking for the presence of the hardcoded account 'disabledsystemuser' in the confluence-users group; its existence indicates the vulnerable app version was installed.
  • Verify exploitation by navigating to the Confluence user profile page after authenticating with the hardcoded credentials; a 302 Location header alone is insufficient and may produce false positives.
  • Check the active user list for the 'disabledsystemuser' account even after uninstalling the Questions for Confluence app, as the account persists post-uninstall.
  • ·The hardcoded account is only created when specific vulnerable versions of the Questions for Confluence app are installed (2.7.34, 2.7.35, 3.0.2); other versions are not affected.
  • ·Atlassian Cloud (atlassian.net-hosted) instances are not affected; only on-premises Confluence Server and Data Center deployments are vulnerable.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.