← Vulnerability feed

Vulnerability record · CVE-2022-26138 · published 20 July 2022

CVE-2022-26138: Atlassian Questions For Confluence hardcoded credentials in disabledsystemuser account

Atlassian · Questions For Confluence

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a user account named disabledsystemuser in the confluence-users group with a hardcoded password. The account is created when installing app versions 2.7.34, 2.7.35, and 3.0.2. Because the password is fixed and the account is a normal group member, any remote attacker who knows the password can log in and read everything that group can access.

9.8 CVSS 3.1 Critical CISA KEV since 29 Jul 2022 EPSS 98% · top 0.1% CWE-798 · Hard-coded credentials
9.8CVSS 3.1 base score
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, CISA KEV listing with a past remediation deadline, and a 0.98 EPSS probability make this an actively exploited, trivially reachable flaw.

What it is

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a user account named disabledsystemuser in the confluence-users group with a hardcoded password. The account is created when installing app versions 2.7.34, 2.7.35, and 3.0.2. Because the password is fixed and the account is a normal group member, any remote attacker who knows the password can log in and read everything that group can access.

Impact

An unauthenticated remote attacker gains a valid Confluence login and can access all content available to the confluence-users group, which typically includes internal pages, spaces and attachments. The CVSS vector rates confidentiality, integrity and availability impact as high, though the description only substantiates content access.

Attack surface

Reachable over the network through the Confluence web login; no authentication and no user interaction are required, only knowledge of the hardcoded password. The account is created automatically at app install, so exposure exists wherever an affected app version was installed.

Exploitation

Listed in CISA KEV with a 2022-08-19 remediation due date, and EPSS probability is 0.9817 (99.9th percentile), indicating observed exploitation and very high likelihood of attempted exploitation. No ransomware campaign use is documented in the record.

What to do

  • Upgrade the Questions For Confluence app to a fixed version per the Atlassian advisory and CONFSERVER-79483, then restart Confluence.
  • If patching is delayed, disable or delete the disabledsystemuser account and remove it from the confluence-users group.
  • Audit Confluence for the disabledsystemuser account and any other unexpected accounts in privileged or content-bearing groups.
  • Restrict network access to Confluence login endpoints to trusted networks or VPN where operationally feasible.
  • Review Confluence access logs for successful logins as disabledsystemuser and rotate any credentials or content that account could reach.

Detection

  • Search Confluence audit and access logs for authentication events or sessions tied to the username disabledsystemuser.
  • Alert on creation or presence of the disabledsystemuser account and on its membership in confluence-users or other groups.
  • Hunt for Questions For Confluence app versions 2.7.34, 2.7.35 or 3.0.2 in installed-app inventories.
  • Monitor for unusual page, space or attachment access from the disabledsystemuser session compared with normal user behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-26138 to the Known Exploited Vulnerabilities catalog on 29 July 2022 as "Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 19 August 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-26138 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.5CVE-2018-13393Atlassian questions for confluence cross-site request forgery vulnerabilityThe convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated t…EPSS 0.80%6.5CVE-2018-13394Atlassian questions for confluence cross-site request forgery vulnerabilityThe acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed …EPSS 0.84%10.0CVE-2026-22769Dell RecoverPoint for Virtual Machines hardcoded credential flawDell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798). An unauthenticated remot…KEVEPSS 13%analysed7.1CVE-2025-14611Gladinet CentreStack and Triofox hardcoded AES key enables file inclusionCentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints.…KEVEPSS 53%analysed6.5CVE-2019-6693FortiOS hard-coded key exposes backup file secretsFortiOS configuration backup files are encrypted with a hard-coded cryptographic key, so anyone who obtains a backup can decrypt the sensitive data i…KEVEPSS 5.8%analysed9.8CVE-2025-30406Gladinet CentreStack hardcoded machineKey deserialization RCEGladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) uses a hardcoded machineKey in the portal's web.config, allowing deserializ…KEVEPSS 94%analysed9.8CVE-2024-20439Cisco Smart Licensing Utility hard-coded admin credential allows remote loginCisco Smart Licensing Utility (CSLU) contains an undocumented static credential for an administrative account. An unauthenticated remote attacker who…KEVEPSS 97%analysed8.1CVE-2021-44207Acclaim USAHERDS hard-coded credentials allow remote compromiseAcclaim USAHERDS through 7.4.0.1 ships with hard-coded credentials (CWE-798). Anyone who knows or extracts those credentials can authenticate to the …KEVEPSS 18%analysed

Source: NIST National Vulnerability Database (record CVE-2022-26138), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.