← Vulnerability feed

Vulnerability record · CVE-2023-22518 · published 31 October 2023

CVE-2023-22518: Atlassian Confluence improper authorization allows admin account creation

Atlassian · Confluence Data Center

Confluence Data Center and Server contain an improper authorization flaw that lets an unauthenticated attacker reset Confluence and create an instance administrator account. That account grants full administrative control, so the flaw threatens complete loss of confidentiality, integrity and availability. Atlassian Cloud sites are not affected.

9.8 CVSS 3.1 Critical CISA KEV since 7 Nov 2023 Known ransomware use EPSS 100% · top 0.1% CWE-863 · Incorrect authorization
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability.  Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable full administrative compromise with active exploitation, KEV listing and near-maximum EPSS score.

What it is

Confluence Data Center and Server contain an improper authorization flaw that lets an unauthenticated attacker reset Confluence and create an instance administrator account. That account grants full administrative control, so the flaw threatens complete loss of confidentiality, integrity and availability. Atlassian Cloud sites are not affected.

Impact

An attacker gains a Confluence instance administrator account and can perform any administrative action, including full compromise of data and service availability.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed Confluence Data Center or Server instance is a candidate target.

Exploitation

CISA added it to KEV on 2023-11-07 with a 2023-11-28 due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99999 and a public exploit reference exists, so exploitation is active and widespread.

What to do

  • Apply the Atlassian vendor patch for Confluence Data Center and Server immediately.
  • If patching is not possible, apply the vendor's documented interim mitigations or take the instance offline.
  • Restrict network access to Confluence instances so they are not reachable from untrusted networks.
  • Audit for unauthorized administrator accounts and remove any that cannot be accounted for.
  • Rotate credentials and secrets stored in or accessible from Confluence after remediation.

Detection

  • Alert on creation of new Confluence administrator accounts, especially outside change windows.
  • Monitor Confluence access logs for unauthenticated requests to setup or administrative endpoints.
  • Hunt for unexpected Confluence configuration resets or setup wizard activity.
  • Correlate Confluence host activity with known ransomware precursor behavior given the KEV ransomware flag.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-22518 to the Known Exploited Vulnerabilities catalog on 7 November 2023 as "Atlassian Confluence Data Center and Server Improper Authorization Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 November 2023.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-22518 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-22527Atlassian Confluence Data Center and Server template injection RCEOlder versions of Confluence Data Center and Server contain a template injection flaw (CWE-74) that lets an unauthenticated attacker execute code on …KEVEPSS 100%analysed9.8CVE-2023-22515Atlassian Confluence Data Center and Server broken access control allows admin account creationConfluence Data Center and Server contain a broken access control flaw that lets an unauthenticated external attacker create unauthorized administrat…KEVEPSS 99%analysed9.8CVE-2022-26134Atlassian Confluence Server and Data Center OGNL injection RCEConfluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker execute arbitrary code on …KEVEPSS 100%analysed9.8CVE-2021-26084Atlassian Confluence Server and Data Center OGNL injection RCEConfluence Server and Data Center contain an OGNL expression language injection flaw that lets an unauthenticated attacker run arbitrary code on the …KEVEPSS 100%analysed9.8CVE-2019-3396Atlassian Confluence Widget Connector path traversal and RCE via SSTIThe Widget Connector macro in Atlassian Confluence Server and Data Center fails to safely handle template input, allowing server-side template inject…KEVEPSS 100%analysed8.8CVE-2019-3398Atlassian Confluence Server path traversal in downloadallattachmentsConfluence Server and Data Center contain a path traversal flaw in the downloadallattachments resource. An attacker with permission to add attachment…KEVEPSS 97%analysed5.3CVE-2021-26085Atlassian Confluence Server pre-auth arbitrary file read via /s/ endpointConfluence Server and Data Center expose a pre-authorization arbitrary file read through the /s/ endpoint, letting unauthenticated remote attackers v…KEVEPSS 100%analysed9.8CVE-2022-26136Atlassian bamboo improper authentication vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps…EPSS 5.4%

Source: NIST National Vulnerability Database (record CVE-2023-22518), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.