← Vulnerability feed

Vulnerability record · CVE-2022-26137 · published 20 July 2022

CVE-2022-26137: Atlassian bamboo origin validation error vulnerability

Atlassian · Bamboo

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim’s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4.

8.8 CVSS 3.1 High EPSS 2.3% · top 17.1% CWE-180 · CWE-180CWE-346 · Origin validation error
8.8CVSS 3.1 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
16References
17 Jun 2026Last modified by NVD

Description

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim’s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://jira.atlassian.com/browse/BAM-21795 Issue TrackingPatchVendor Advisory
https://jira.atlassian.com/browse/BSERV-13370 Issue TrackingPatchVendor Advisory
https://jira.atlassian.com/browse/CONFSERVER-79476 Issue TrackingPatchVendor Advisory
https://jira.atlassian.com/browse/CRUC-8541 Issue TrackingPatchVendor Advisory
https://jira.atlassian.com/browse/CWD-5815 Issue TrackingPatchVendor Advisory
https://jira.atlassian.com/browse/FE-7410 Issue TrackingPatchVendor Advisory
https://jira.atlassian.com/browse/JRASERVER-73897 Issue TrackingPatchVendor Advisory
https://jira.atlassian.com/browse/JSDSERVER-11863 Issue TrackingPatchVendor Advisory
https://jira.atlassian.com/browse/BAM-21795 Issue TrackingPatchVendor Advisory
https://jira.atlassian.com/browse/BSERV-13370 Issue TrackingPatchVendor Advisory
https://jira.atlassian.com/browse/CONFSERVER-79476 Issue TrackingPatchVendor Advisory
https://jira.atlassian.com/browse/CRUC-8541 Issue TrackingPatchVendor Advisory
https://jira.atlassian.com/browse/CWD-5815 Issue TrackingPatchVendor Advisory
https://jira.atlassian.com/browse/FE-7410 Issue TrackingPatchVendor Advisory
https://jira.atlassian.com/browse/JRASERVER-73897 Issue TrackingPatchVendor Advisory
https://jira.atlassian.com/browse/JSDSERVER-11863 Issue TrackingPatchVendor Advisory

Track CVE-2022-26137 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-22527Atlassian Confluence Data Center and Server template injection RCEOlder versions of Confluence Data Center and Server contain a template injection flaw (CWE-74) that lets an unauthenticated attacker execute code on …KEVEPSS 100%analysed9.8CVE-2023-22518Atlassian Confluence improper authorization allows admin account creationConfluence Data Center and Server contain an improper authorization flaw that lets an unauthenticated attacker reset Confluence and create an instanc…KEVEPSS 100%analysed9.8CVE-2023-22515Atlassian Confluence Data Center and Server broken access control allows admin account creationConfluence Data Center and Server contain a broken access control flaw that lets an unauthenticated external attacker create unauthorized administrat…KEVEPSS 99%analysed9.8CVE-2022-26134Atlassian Confluence Server and Data Center OGNL injection RCEConfluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker execute arbitrary code on …KEVEPSS 100%analysed9.8CVE-2021-26084Atlassian Confluence Server and Data Center OGNL injection RCEConfluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker run arbitrary code on the …KEVEPSS 100%analysed9.8CVE-2019-11580Atlassian Crowd pdkinstall plugin allows unauthenticated remote code executionAtlassian Crowd and Crowd Data Center shipped release builds with the pdkinstall development plugin incorrectly enabled. An attacker who can reach th…KEVEPSS 95%analysed9.8CVE-2019-3396Atlassian Confluence Widget Connector path traversal and RCE via SSTIThe Widget Connector macro in Atlassian Confluence Server and Data Center fails to safely handle template input, allowing server-side template inject…KEVEPSS 100%analysed8.8CVE-2022-36804Atlassian Bitbucket Server and Data Center API command injectionMultiple API endpoints in Atlassian Bitbucket Server and Data Center fail to properly neutralize command and argument input, allowing OS command inje…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2022-26137), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.