Vulnerability record · CVE-2022-26134 · published 3 June 2022
CVE-2022-26134: Atlassian Confluence Server and Data Center OGNL injection RCE
Atlassian · Confluence Data Center
Confluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker execute arbitrary code on the instance. It affects a wide range of versions from 1.3.0 through the 7.18.x line, so most unpatched deployments are exposed. Because it is remotely reachable without credentials, it is a top-tier target for mass exploitation.
Description
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with near-certain exploitation likelihood, active KEV listing, and documented ransomware use.
What it is
Confluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker execute arbitrary code on the instance. It affects a wide range of versions from 1.3.0 through the 7.18.x line, so most unpatched deployments are exposed. Because it is remotely reachable without credentials, it is a top-tier target for mass exploitation.
Impact
An attacker gains remote code execution on the Confluence host, which typically means full control of the application and its data, and potentially the underlying server. This can lead to data theft, ransomware deployment, or use of the host as a pivot into the network.
Attack surface
The vulnerability is network-reachable over HTTP/HTTPS with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed or internally reachable Confluence Server or Data Center instance in an affected version is a candidate.
Exploitation
CISA added it to KEV on 2022-06-02 with a 2022-06-06 remediation due date and flagged known ransomware campaign use; EPSS is near 1.0 (0.99999, 99.993rd percentile). Multiple public exploit and proof-of-concept references exist, so exploitation is trivial and widespread.
What to do
- Upgrade to a fixed Confluence release per the Atlassian advisory (7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, or 7.18.1 and later as applicable).
- If patching cannot be done immediately, block all internet traffic to and from affected Confluence instances, as CISA directed.
- Restrict network access to Confluence to trusted management networks and remove direct public exposure where possible.
- After patching, hunt for prior compromise and rotate credentials and secrets stored in or accessible from Confluence.
- Monitor vendor advisory and CISA KEV guidance for any updated remediation steps.
Detection
- Review Confluence access logs for suspicious requests containing OGNL or expression-language payloads (for example ${...} patterns) in URLs or parameters.
- Look for unexpected child processes spawned by the Confluence Java process, such as shells or command interpreters.
- Check for newly created files, webshells, or modified JSP/plugin content under the Confluence installation and data directories.
- Correlate outbound network connections from the Confluence host to unfamiliar destinations, which may indicate post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-26134 to the Known Exploited Vulnerabilities catalog on 2 June 2022 as "Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules. Federal deadline 6 June 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-26134 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-26134), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.