Vulnerability record · CVE-2023-22518 · published 31 October 2023
CVE-2023-22518: Atlassian Confluence improper authorization allows admin account creation
Atlassian · Confluence Data Center
Confluence Data Center and Server contain an improper authorization flaw that lets an unauthenticated attacker reset Confluence and create an instance administrator account. That account grants full administrative control, so the flaw threatens complete loss of confidentiality, integrity and availability. Atlassian Cloud sites are not affected.
Description
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable full administrative compromise with active exploitation, KEV listing and near-maximum EPSS score.
What it is
Confluence Data Center and Server contain an improper authorization flaw that lets an unauthenticated attacker reset Confluence and create an instance administrator account. That account grants full administrative control, so the flaw threatens complete loss of confidentiality, integrity and availability. Atlassian Cloud sites are not affected.
Impact
An attacker gains a Confluence instance administrator account and can perform any administrative action, including full compromise of data and service availability.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed Confluence Data Center or Server instance is a candidate target.
Exploitation
CISA added it to KEV on 2023-11-07 with a 2023-11-28 due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99999 and a public exploit reference exists, so exploitation is active and widespread.
What to do
- Apply the Atlassian vendor patch for Confluence Data Center and Server immediately.
- If patching is not possible, apply the vendor's documented interim mitigations or take the instance offline.
- Restrict network access to Confluence instances so they are not reachable from untrusted networks.
- Audit for unauthorized administrator accounts and remove any that cannot be accounted for.
- Rotate credentials and secrets stored in or accessible from Confluence after remediation.
Detection
- Alert on creation of new Confluence administrator accounts, especially outside change windows.
- Monitor Confluence access logs for unauthenticated requests to setup or administrative endpoints.
- Hunt for unexpected Confluence configuration resets or setup wizard activity.
- Correlate Confluence host activity with known ransomware precursor behavior given the KEV ransomware flag.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-22518 to the Known Exploited Vulnerabilities catalog on 7 November 2023 as "Atlassian Confluence Data Center and Server Improper Authorization Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 November 2023.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/176264/Atlassian-Confluence-Improper-Authorization-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://confluence.atlassian.com/pages/viewpage.action?pageId=1311473907 | Issue TrackingMitigationVendor Advisory |
| https://jira.atlassian.com/browse/CONFSERVER-93142 | Issue TrackingMitigationVendor Advisory |
| http://packetstormsecurity.com/files/176264/Atlassian-Confluence-Improper-Authorization-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://confluence.atlassian.com/pages/viewpage.action?pageId=1311473907 | Issue TrackingMitigationVendor Advisory |
| https://jira.atlassian.com/browse/CONFSERVER-93142 | Issue TrackingMitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22518 | US Government Resource |
Track CVE-2023-22518 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-22518), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.