← Vulnerability feed

Vulnerability record · CVE-2022-43781 · published 17 November 2022

CVE-2022-43781: Bitbucket Server and Data Center command injection via environment variables

Atlassian · Bitbucket

Bitbucket Server and Data Center contains a command injection flaw (CWE-77) reachable through environment variables. An attacker who can control their username can inject commands and execute arbitrary code on the host. If "Allow public signup" is enabled, the issue is exploitable without authentication, making exposure severe for internet-facing instances.

9.8 CVSS 3.1 Critical EPSS 98% · top 0.1% CWE-77 · Command injection
9.8CVSS 3.1 base score
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no privileges or interaction required under public signup, and an EPSS near 0.98 make this a top-priority patch.

What it is

Bitbucket Server and Data Center contains a command injection flaw (CWE-77) reachable through environment variables. An attacker who can control their username can inject commands and execute arbitrary code on the host. If "Allow public signup" is enabled, the issue is exploitable without authentication, making exposure severe for internet-facing instances.

Impact

Successful exploitation gives the attacker arbitrary code execution on the Bitbucket server, with high impact to confidentiality, integrity and availability of the application and its data.

Attack surface

Reached over the network via the application's username handling; no user interaction is required. Authentication is normally needed, but the flaw becomes unauthenticated when public signup is enabled, matching the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.98, 99.9th percentile), indicating strong likelihood of exploitation activity. References are vendor advisory, patch and mitigation pages only, with no public exploit tag.

What to do

  • Upgrade Bitbucket Server and Data Center to the fixed version listed in the Atlassian advisory (BSERV-13522) as the first action.
  • If immediate patching is not possible, apply the mitigations in the Atlassian advisory and restrict network access to the instance.
  • Disable "Allow public signup" so the flaw requires authentication.
  • Restrict and audit who can create accounts or control usernames on the instance.
  • Place the instance behind access controls or a VPN rather than exposing it directly to the internet.

Detection

  • Review Bitbucket server logs for unusual usernames containing shell metacharacters or command-like strings.
  • Monitor for unexpected child processes spawned by the Bitbucket service account.
  • Alert on new account creation or signup activity, especially where public signup is enabled.
  • Hunt for outbound connections or file changes originating from the Bitbucket host that do not match normal application behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://confluence.atlassian.com/x/Y4hXRg MitigationRelease NotesVendor Advisory
https://jira.atlassian.com/browse/BSERV-13522 Issue TrackingPatchVendor Advisory
https://confluence.atlassian.com/x/Y4hXRg MitigationRelease NotesVendor Advisory
https://jira.atlassian.com/browse/BSERV-13522 Issue TrackingPatchVendor Advisory

Track CVE-2022-43781 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-36804Atlassian Bitbucket Server and Data Center API command injectionMultiple API endpoints in Atlassian Bitbucket Server and Data Center fail to properly neutralize command and argument input, allowing OS command inje…KEVEPSS 99%analysed9.9CVE-2018-5225Atlassian bitbucket link following vulnerabilityIn browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (t…EPSS 3.4%9.8CVE-2022-26136Atlassian bamboo improper authentication vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps…EPSS 5.4%9.8CVE-2019-15000Atlassian bitbucket os command injection vulnerabilityThe commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed…EPSS 7.8%9.1CVE-2019-3397Atlassian bitbucket path traversal vulnerabilityAtlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14…EPSS 4.4%8.8CVE-2022-26137Atlassian bamboo origin validation error vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the a…EPSS 2.3%8.8CVE-2019-15010Atlassian bitbucket command injection vulnerabilityBitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from versio…EPSS 2.6%8.8CVE-2019-15012Atlassian bitbucket improper privilege management vulnerabilityBitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2022-43781), CISA KEV, FIRST EPSS (scores of 2026-09-19). This page is refreshed as NVD updates the record.