← Vulnerability feed

Vulnerability record · CVE-2022-26134 · published 3 June 2022

CVE-2022-26134: Atlassian Confluence Server and Data Center OGNL injection RCE

Atlassian · Confluence Data Center

Confluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker execute arbitrary code on the instance. It affects a wide range of versions from 1.3.0 through the 7.18.x line, so most unpatched deployments are exposed. Because it is remotely reachable without credentials, it is a top-tier target for mass exploitation.

9.8 CVSS 3.1 Critical CISA KEV since 2 Jun 2022 Known ransomware use EPSS 100% · top 0.1% CWE-917 · Expression language injection
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
13References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with near-certain exploitation likelihood, active KEV listing, and documented ransomware use.

What it is

Confluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker execute arbitrary code on the instance. It affects a wide range of versions from 1.3.0 through the 7.18.x line, so most unpatched deployments are exposed. Because it is remotely reachable without credentials, it is a top-tier target for mass exploitation.

Impact

An attacker gains remote code execution on the Confluence host, which typically means full control of the application and its data, and potentially the underlying server. This can lead to data theft, ransomware deployment, or use of the host as a pivot into the network.

Attack surface

The vulnerability is network-reachable over HTTP/HTTPS with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed or internally reachable Confluence Server or Data Center instance in an affected version is a candidate.

Exploitation

CISA added it to KEV on 2022-06-02 with a 2022-06-06 remediation due date and flagged known ransomware campaign use; EPSS is near 1.0 (0.99999, 99.993rd percentile). Multiple public exploit and proof-of-concept references exist, so exploitation is trivial and widespread.

What to do

  • Upgrade to a fixed Confluence release per the Atlassian advisory (7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, or 7.18.1 and later as applicable).
  • If patching cannot be done immediately, block all internet traffic to and from affected Confluence instances, as CISA directed.
  • Restrict network access to Confluence to trusted management networks and remove direct public exposure where possible.
  • After patching, hunt for prior compromise and rotate credentials and secrets stored in or accessible from Confluence.
  • Monitor vendor advisory and CISA KEV guidance for any updated remediation steps.

Detection

  • Review Confluence access logs for suspicious requests containing OGNL or expression-language payloads (for example ${...} patterns) in URLs or parameters.
  • Look for unexpected child processes spawned by the Confluence Java process, such as shells or command interpreters.
  • Check for newly created files, webshells, or modified JSP/plugin content under the Confluence installation and data directories.
  • Correlate outbound network connections from the Confluence host to unfamiliar destinations, which may indicate post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-26134 to the Known Exploited Vulnerabilities catalog on 2 June 2022 as "Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules. Federal deadline 6 June 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/167430/Confluence-OGNL-Injection-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/167431/Through-The-Wire-CVE-2022-26134-Confluence-Proof-Of-Concept.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/167432/Confluence-OGNL-Injection-Proof-Of-Concept.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGNL-Injection.html ExploitThird Party AdvisoryVDB Entry
https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html Vendor Advisory
https://jira.atlassian.com/browse/CONFSERVER-79016 Issue TrackingPatchVendor Advisory
http://packetstormsecurity.com/files/167430/Confluence-OGNL-Injection-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/167431/Through-The-Wire-CVE-2022-26134-Confluence-Proof-Of-Concept.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/167432/Confluence-OGNL-Injection-Proof-Of-Concept.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGNL-Injection.html ExploitThird Party AdvisoryVDB Entry
https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html Vendor Advisory
https://jira.atlassian.com/browse/CONFSERVER-79016 Issue TrackingPatchVendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26134 US Government Resource

Track CVE-2022-26134 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-22527Atlassian Confluence Data Center and Server template injection RCEOlder versions of Confluence Data Center and Server contain a template injection flaw (CWE-74) that lets an unauthenticated attacker execute code on …KEVEPSS 100%analysed9.8CVE-2023-22518Atlassian Confluence improper authorization allows admin account creationConfluence Data Center and Server contain an improper authorization flaw that lets an unauthenticated attacker reset Confluence and create an instanc…KEVEPSS 100%analysed9.8CVE-2023-22515Atlassian Confluence Data Center and Server broken access control allows admin account creationConfluence Data Center and Server contain a broken access control flaw that lets an unauthenticated external attacker create unauthorized administrat…KEVEPSS 99%analysed9.8CVE-2021-26084Atlassian Confluence Server and Data Center OGNL injection RCEConfluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker run arbitrary code on the …KEVEPSS 100%analysed9.8CVE-2019-3396Atlassian Confluence Widget Connector path traversal and RCE via SSTIThe Widget Connector macro in Atlassian Confluence Server and Data Center fails to safely handle template input, allowing server-side template inject…KEVEPSS 100%analysed8.8CVE-2019-3398Atlassian Confluence Server path traversal in downloadallattachmentsConfluence Server and Data Center contain a path traversal flaw in the downloadallattachments resource. An attacker with permission to add attachment…KEVEPSS 97%analysed5.3CVE-2021-26085Atlassian Confluence Server pre-auth arbitrary file read via /s/ endpointConfluence Server and Data Center expose a pre-authorization arbitrary file read through the /s/ endpoint, letting unauthenticated remote attackers v…KEVEPSS 100%analysed9.8CVE-2022-26136Atlassian bamboo improper authentication vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps…EPSS 5.4%

Source: NIST National Vulnerability Database (record CVE-2022-26134), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.