LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-26134: Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 2, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 6, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-26134 to its Known Exploited Vulnerabilities catalog on Jun 2, 2022, with a federal patch deadline of Jun 6, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.

CVE-2022-26134 is a remote code execution vulnerability in Atlassian Confluence Server and Data Center. An unauthenticated attacker can exploit it to run code on the affected system. It matters because Confluence often holds internal documentation and collaboration data, is frequently reachable from the network, and this issue has been used in ransomware activity. Teams should treat internet-facing instances as high priority and confirm all version and fix details against the vendor advisory.

How it works

The weakness is classified as CWE-917 (Expression Language Injection). In products that evaluate expression language in user-controlled input, an attacker who can supply crafted expressions may cause the application to evaluate them in an unsafe way. For this Confluence vulnerability, CISA describes an unauthenticated remote code execution path: an attacker who can reach the vulnerable service does not need valid credentials to trigger code execution on the host.

Exact request paths, payloads, and preconditions are not repeated here; defenders should obtain those only from the official Atlassian security advisory and validated detection content. The practical impact is full compromise of the Confluence process and, depending on privileges and host configuration, further movement into the surrounding environment.

Am I affected? How to find it in your systems

Confluence Server and Data Center typically run as on-premises or self-managed Java web applications behind a reverse proxy or load balancer, often on internal wikis, intranet portals, or project spaces. Cloud-hosted Atlassian Confluence is a different deployment model; focus inventory on self-managed Server and Data Center instances.

How to remediate

Patch first. Apply the update published in Atlassian’s security advisory for CVE-2022-26134 (the advisory referenced in CISA’s required action). Follow vendor install and restart procedures, then verify the running version matches a fixed release.

If you can't patch immediately

Use compensating controls until the vendor update is applied.

If your data may have been exposed

This vulnerability enables unauthenticated remote code execution and has known ransomware use. If your Confluence instance was reachable and unpatched during the exploitation window, assume possible host compromise, credential theft, and access to content stored in Confluence. Isolate affected systems, rotate secrets and service account credentials, review outbound data transfers, and follow your incident response process. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAtlassian · Confluence Server/Data Center
WeaknessCWE-917
Added to CISA KEVJun 2, 2022
Federal patch deadlineJun 6, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities