Vulnerability record · CVE-2022-26133 · published 20 April 2022
CVE-2022-26133: Atlassian Bitbucket Data Center Java deserialization RCE
Atlassian · Bitbucket Data Center
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center fails to safely handle deserialized data, allowing remote code execution. The flaw affects multiple version branches from 5.14.0 onward and is reachable without authentication, making it a serious risk for exposed Data Center deployments.
Description
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network-reachable, unauthenticated remote code execution and very high EPSS make this an urgent patching priority.
What it is
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center fails to safely handle deserialized data, allowing remote code execution. The flaw affects multiple version branches from 5.14.0 onward and is reachable without authentication, making it a serious risk for exposed Data Center deployments.
Impact
An unauthenticated attacker can execute arbitrary code on the Bitbucket Data Center server, gaining full control of the application and potentially the underlying host.
Attack surface
The vulnerability is network-reachable (CVSS AV:N) with no privileges or user interaction required (PR:N, UI:N), so any attacker who can reach the affected service can attempt exploitation.
Exploitation
The record shows no CISA KEV listing and no public exploit references, but EPSS is very high at roughly 0.70 (99th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade Bitbucket Data Center to a fixed release: 7.6.14, 7.17.6, 7.18.4, or 7.19.4 and later, per the vendor advisory.
- Restrict network access to Bitbucket Data Center cluster/authentication endpoints to trusted hosts only.
- Monitor the vendor advisory and Jira issue BSERV-13173 for updated guidance and patches.
- If immediate patching is not possible, isolate the instance behind a reverse proxy or firewall rules limiting exposure.
Detection
- Monitor application and system logs for unexpected deserialization errors or Java exceptions from SharedSecretClusterAuthenticator.
- Alert on outbound network connections or process spawning from the Bitbucket Data Center host that are not part of normal operations.
- Watch for unusual authentication attempts or traffic to cluster-related endpoints from untrusted source IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://confluence.atlassian.com/security/multiple-products-security-advisory-hazelcast-vulnerable-to-remote-code-execut | PatchVendor Advisory |
| https://jira.atlassian.com/browse/BSERV-13173 | Vendor Advisory |
| https://confluence.atlassian.com/security/multiple-products-security-advisory-hazelcast-vulnerable-to-remote-code-execut | PatchVendor Advisory |
| https://jira.atlassian.com/browse/BSERV-13173 | Vendor Advisory |
Track CVE-2022-26133 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-26133), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.