CVE-2022-26134 Details
Description
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.
A critical remote code execution vulnerability has been identified in Atlassian Confluence Server and Data Center. This vulnerability arises from OGNL injection, allowing an unauthenticated attacker to execute arbitrary code on the affected Confluence instance. The vulnerability affects all versions of Confluence Server and Data Center from 1.3.0 prior to 7.4.17, as well as versions 7.13.0 prior to 7.13.7, 7.14.0 prior to 7.14.3, 7.15.0 prior to 7.15.2, 7.16.0 prior to 7.16.4, 7.17.0 prior to 7.17.4, and 7.18.0 prior to 7.18.1.
Users are advised to upgrade to Confluence versions 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4 or 7.18.1. For those unable to upgrade immediately, a temporary mitigation involves replacing specific JAR files in the Confluence installation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability | Jun 2, 2022 | Jun 6, 2022 | Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-917 | Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') | [email protected] |
| CWE-917 | Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| atlassian confluence data center | >= 1.3, < 7.4.17 >= 7.13.0, < 7.13.7 >= 7.14.0, < 7.14.3 >= 7.15.0, < 7.15.2 >= 7.16.0, < 7.16.4 >= 7.17.0, < 7.17.4 7.18.0 |
CPE
Remediation
| |
| atlassian confluence server | >= 1.3, < 7.4.17 >= 7.13.0, < 7.13.7 >= 7.14.0, < 7.14.3 >= 7.15.0, < 7.15.2 >= 7.16.0, < 7.16.4 >= 7.17.0, < 7.17.4 7.18.0 |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 24, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Feb 9, 2025 | Modified Analysis | [email protected] |
| Feb 4, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 28, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 8, 2023 | CWE Remap | [email protected] |
| Jun 30, 2022 | CVE Modified | [email protected] |
| Jun 14, 2022 | Initial Analysis | [email protected] |
| Jun 8, 2022 | CVE Modified | [email protected] |
| Jun 8, 2022 | CVE Modified | [email protected] |