Vulnerability record · CVE-2023-22515 · published 4 October 2023
CVE-2023-22515: Atlassian Confluence Data Center and Server broken access control allows admin account creation
Atlassian · Confluence Data Center
Confluence Data Center and Server contain a broken access control flaw that lets an unauthenticated external attacker create unauthorized administrator accounts. Atlassian confirmed a handful of customers had already been exploited, and the issue is remotely reachable on publicly accessible instances. Atlassian Cloud sites (atlassian.net domains) are not affected.
Description
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable flaw with CVSS 9.8, confirmed in-the-wild exploitation, KEV listing with known ransomware use and near-maximum EPSS score.
What it is
Confluence Data Center and Server contain a broken access control flaw that lets an unauthenticated external attacker create unauthorized administrator accounts. Atlassian confirmed a handful of customers had already been exploited, and the issue is remotely reachable on publicly accessible instances. Atlassian Cloud sites (atlassian.net domains) are not affected.
Impact
An attacker gains full Confluence administrator access, which can lead to data theft, configuration changes and, per the referenced exploit material, remote code execution. Because the created accounts are legitimate admin accounts, activity can blend into normal administration.
Attack surface
Reachable over the network with no authentication and no user interaction (CVSS vector AV:N/AC:L/PR:N/UI:N). Only publicly accessible Confluence Data Center and Server instances are exposed; Atlassian-hosted Cloud sites are not.
Exploitation
CISA added it to KEV on 2023-10-05 with a 2023-10-13 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99156 (99.9th percentile). Public exploit code is referenced (Packet Storm), so exploitation is active and widespread.
What to do
- Upgrade Confluence Data Center and Server to a vendor-fixed version immediately; follow the Atlassian advisory and FAQ for CVE-2023-22515.
- If patching cannot be done at once, apply Atlassian's documented interim mitigations or take the instance off the public internet.
- Audit all Confluence instances for unauthorized administrator accounts and remove any that are not legitimate.
- Restrict network access to Confluence admin interfaces and limit exposure of the instance to trusted networks.
- Treat any confirmed compromise as a full incident: rotate credentials, review logs and report positive findings to CISA per the KEV required action.
Detection
- Hunt for newly created or unexpected Confluence administrator accounts, especially accounts created outside change windows.
- Review Confluence access and audit logs for unauthenticated requests to administrative or setup endpoints preceding account creation.
- Monitor for the exploit activity described in public exploit write-ups and correlate with outbound or post-exploitation behavior.
- Check for signs of ransomware staging or lateral movement on hosts running Confluence, given the KEV ransomware flag.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-22515 to the Known Exploited Vulnerabilities catalog on 5 October 2023 as "Atlassian Confluence Data Center and Server Broken Access Control Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA. Federal deadline 13 October 2023.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/175225/Atlassian-Confluence-Unauthenticated-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://confluence.atlassian.com/display/KB/FAQ+for+CVE-2023-22515 | Vendor Advisory |
| https://confluence.atlassian.com/pages/viewpage.action?pageId=1295682276 | Vendor Advisory |
| https://jira.atlassian.com/browse/CONFSERVER-92475 | Issue TrackingVendor Advisory |
| http://packetstormsecurity.com/files/175225/Atlassian-Confluence-Unauthenticated-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://confluence.atlassian.com/display/KB/FAQ+for+CVE-2023-22515 | Vendor Advisory |
| https://confluence.atlassian.com/pages/viewpage.action?pageId=1295682276 | Vendor Advisory |
| https://jira.atlassian.com/browse/CONFSERVER-92475 | Issue TrackingVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22515 | US Government Resource |
Track CVE-2023-22515 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-22515), CISA KEV, FIRST EPSS (scores of 2026-09-17). This page is refreshed as NVD updates the record.