← Vulnerability feed

Vulnerability record · CVE-2022-26133 · published 20 April 2022

CVE-2022-26133: Atlassian Bitbucket Data Center Java deserialization RCE

Atlassian · Bitbucket Data Center

SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center fails to safely handle deserialized data, allowing remote code execution. The flaw affects multiple version branches from 5.14.0 onward and is reachable without authentication, making it a serious risk for exposed Data Center deployments.

9.8 CVSS 3.1 Critical EPSS 70% · top 0.6% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network-reachable, unauthenticated remote code execution and very high EPSS make this an urgent patching priority.

What it is

SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center fails to safely handle deserialized data, allowing remote code execution. The flaw affects multiple version branches from 5.14.0 onward and is reachable without authentication, making it a serious risk for exposed Data Center deployments.

Impact

An unauthenticated attacker can execute arbitrary code on the Bitbucket Data Center server, gaining full control of the application and potentially the underlying host.

Attack surface

The vulnerability is network-reachable (CVSS AV:N) with no privileges or user interaction required (PR:N, UI:N), so any attacker who can reach the affected service can attempt exploitation.

Exploitation

The record shows no CISA KEV listing and no public exploit references, but EPSS is very high at roughly 0.70 (99th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Upgrade Bitbucket Data Center to a fixed release: 7.6.14, 7.17.6, 7.18.4, or 7.19.4 and later, per the vendor advisory.
  • Restrict network access to Bitbucket Data Center cluster/authentication endpoints to trusted hosts only.
  • Monitor the vendor advisory and Jira issue BSERV-13173 for updated guidance and patches.
  • If immediate patching is not possible, isolate the instance behind a reverse proxy or firewall rules limiting exposure.

Detection

  • Monitor application and system logs for unexpected deserialization errors or Java exceptions from SharedSecretClusterAuthenticator.
  • Alert on outbound network connections or process spawning from the Bitbucket Data Center host that are not part of normal operations.
  • Watch for unusual authentication attempts or traffic to cluster-related endpoints from untrusted source IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-26133 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-22513Atlassian bitbucket data center code injection vulnerabilityThis High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Co…EPSS 16%4.3CVE-2024-21684Atlassian bitbucket data center open redirect vulnerabilityThere is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 …EPSS 0.25%9.8CVE-2021-23758Ajax.NET Professional ajaxpro.2 untrusted deserialization RCEAll versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That l…KEVEPSS 83%analysed9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 90%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed8.8CVE-2026-45659Microsoft SharePoint Server deserialization flaw enables remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an authenticated attacker run code over the network. The flaw is remotely reachable,…KEVEPSS 2.7%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2022-26133), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.