LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-22518: Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 7, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 28, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-22518 to its Known Exploited Vulnerabilities catalog on Nov 7, 2023, with a federal patch deadline of Nov 28, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact…

CVE-2023-22518 is an improper authorization vulnerability in Atlassian Confluence Data Center and Server. An unauthenticated attacker can exploit it to cause significant data loss. Confidentiality is not affected because the attacker cannot exfiltrate data. The issue has been used by ransomware operators, so organizations running Confluence should treat it as high priority and confirm all details against the vendor advisory.

This guidance helps IT and security teams understand the risk, locate affected instances, and reduce exposure until patches or other controls are in place.

How it works

The vulnerability is classified as CWE-863 (Improper Authorization). In this class of flaw, the application fails to correctly enforce access controls on certain operations. An unauthenticated remote attacker can invoke those operations without valid credentials or privileges.

According to the CISA summary, successful exploitation results in significant data loss on the Confluence instance. The attacker cannot read or steal data, so confidentiality impact is none; the primary harm is integrity and availability of content stored in Confluence. Exact request paths, parameters, or payload formats are not detailed here and must be confirmed from the vendor advisory. Because the attack requires no authentication, any internet-facing or poorly segmented Confluence server is a realistic target.

Am I affected? How to find it in your systems

Atlassian Confluence Data Center and Server are the products in scope. Confluence is commonly deployed as an internal wiki, knowledge base, or collaboration platform, often reachable via reverse proxies or load balancers. It may run on-premises, in private clouds, or in hybrid environments.

If you cannot determine version or exposure status, treat the instance as potentially vulnerable until verified.

How to remediate

The primary remediation is to apply the vendor-supplied update that addresses CVE-2023-22518. Follow Atlassian’s official instructions for upgrading Confluence Data Center or Server, including any required database or plugin compatibility steps. After patching, restart services and verify the new version string.

CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Prioritize internet-facing instances first.

If you can't patch immediately

When an immediate upgrade is not feasible, apply compensating controls to reduce the attack surface while planning the patch window.

If your data may have been exposed

This vulnerability has been observed in ransomware campaigns. Although the flaw itself does not allow data exfiltration, ransomware operators often combine it with other techniques to encrypt or destroy data and demand payment. If you discover evidence of exploitation—missing pages, emptied spaces, or ransomware notes—activate your incident-response plan, preserve logs and snapshots, and engage forensic support.

Even when Confluence data itself was not stolen, attackers may have used the foothold for further movement. Review adjacent systems for compromise. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether related credentials have appeared in other incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAtlassian · Confluence Data Center and Server
WeaknessCWE-863
Added to CISA KEVNov 7, 2023
Federal patch deadlineNov 28, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities