Vulnerability record · CVE-2022-26138 · published 20 July 2022
CVE-2022-26138: Atlassian Questions For Confluence hardcoded credentials in disabledsystemuser account
Atlassian · Questions For Confluence
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a user account named disabledsystemuser in the confluence-users group with a hardcoded password. The account is created when installing app versions 2.7.34, 2.7.35, and 3.0.2. Because the password is fixed and the account is a normal group member, any remote attacker who knows the password can log in and read everything that group can access.
Description
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing with a past remediation deadline, and a 0.98 EPSS probability make this an actively exploited, trivially reachable flaw.
What it is
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a user account named disabledsystemuser in the confluence-users group with a hardcoded password. The account is created when installing app versions 2.7.34, 2.7.35, and 3.0.2. Because the password is fixed and the account is a normal group member, any remote attacker who knows the password can log in and read everything that group can access.
Impact
An unauthenticated remote attacker gains a valid Confluence login and can access all content available to the confluence-users group, which typically includes internal pages, spaces and attachments. The CVSS vector rates confidentiality, integrity and availability impact as high, though the description only substantiates content access.
Attack surface
Reachable over the network through the Confluence web login; no authentication and no user interaction are required, only knowledge of the hardcoded password. The account is created automatically at app install, so exposure exists wherever an affected app version was installed.
Exploitation
Listed in CISA KEV with a 2022-08-19 remediation due date, and EPSS probability is 0.9817 (99.9th percentile), indicating observed exploitation and very high likelihood of attempted exploitation. No ransomware campaign use is documented in the record.
What to do
- Upgrade the Questions For Confluence app to a fixed version per the Atlassian advisory and CONFSERVER-79483, then restart Confluence.
- If patching is delayed, disable or delete the disabledsystemuser account and remove it from the confluence-users group.
- Audit Confluence for the disabledsystemuser account and any other unexpected accounts in privileged or content-bearing groups.
- Restrict network access to Confluence login endpoints to trusted networks or VPN where operationally feasible.
- Review Confluence access logs for successful logins as disabledsystemuser and rotate any credentials or content that account could reach.
Detection
- Search Confluence audit and access logs for authentication events or sessions tied to the username disabledsystemuser.
- Alert on creation or presence of the disabledsystemuser account and on its membership in confluence-users or other groups.
- Hunt for Questions For Confluence app versions 2.7.34, 2.7.35 or 3.0.2 in installed-app inventories.
- Monitor for unusual page, space or attachment access from the disabledsystemuser session compared with normal user behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-26138 to the Known Exploited Vulnerabilities catalog on 29 July 2022 as "Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 19 August 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://confluence.atlassian.com/doc/confluence-security-advisory-2022-07-20-1142446709.html | Vendor Advisory |
| https://jira.atlassian.com/browse/CONFSERVER-79483 | Issue TrackingPatchVendor Advisory |
| https://confluence.atlassian.com/doc/confluence-security-advisory-2022-07-20-1142446709.html | Vendor Advisory |
| https://jira.atlassian.com/browse/CONFSERVER-79483 | Issue TrackingPatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26138 | US Government Resource |
Track CVE-2022-26138 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-26138), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.