CVE-2022-26134
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.
- Affected products
- Confluence
- Atlassian Confluence Data Center
- < 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, 7.18.0
- Atlassian Confluence Server
- < 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, 7.18.0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-917
- NVD status
- Analyzed
- Published
- 2022-06-03
CVE-2022-26134 at NVD
100 known exploits for CVE-2022-26134
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2022-26134
exploit_CVE-2022-26134
confluencePot
CVE-2022-26134
CVE-2022-26134
CVE-2022-26134
-CVE-2022-26134
BotCon
CVE-2022-26134
CVE-2022-26134
CVE-2022-26134
CVE-2022-26134
CVE-2022-26134_conFLU
CVE-2022-26134
CVE-2022-26134-Confluence
CVE-2022-26134
CVE-2022-26134
cve-2022-26134
CVE-2022-26134-Confluence-RCE
ATLASSIAN-Confluence_rce
Atlassian-CVE-2022-26134
CVE-2022-26134-PoC
ConfluentPwn
CVE-2022-26134
CVE-2022-26134-cve1
CVE-2022-26134
cve-2022-26134
CVE-2022-26134
CVE-2022-26134
CVE-2022-26134
CVE-2022-26134
Confluence-CVE-2022-26134
TryHackMe-Atlassian-CVE-2022-26134
CVE-2022-26134_check
Confluence-CVE-2022-26134
CVE-2022-26134
CVE-2022-26134-Console
CVE-2022-26134
CVE-2022-26134-OGNL-Injection
CVE-2022-26134
CVE-2022-26134
cve-2022-26134
confusploit
CVE-2022-26134
CVE-2022-26134_Behinder_MemShell
CVE-2022-26134
CVE-2022-26134
Confluence-CVE-2022-26134
CVE-2022-26134-LAB
cve-2022-26134
CVE-2022-26134
Atlassian_CVE-2022-26134
CVE-2022-26134
CVE-2020-13937
CVE-2022-26134
CVE-2022-26134
CVE-2022-26134
CVE-2022-26134
CVE-2022-26134-POC
CVE-2022-26134
through_the_wire
confluence-ognl-rce
CVE-2022-26134
cve-2022-26134
CVE-2022-26134-Godzilla-MEMSHELL
CVE-2022-26134
CVE-2022-26134web
CVE-2022-26134
security-labs-pocs
CVE-2022-26134
CVE-2021-46422
CVE-2022-26134-Exploit-Detection
CVE-2022-26134
CVE-2022-36553-PoC
CVE-2022-26134
APT-Backpack
CVE-Confluence
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Command Injection in Hytec Hwl-2511-Ss_Firmware
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Improper Access Control in Joomla Joomla!
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Uncontrolled Resource Consumption in Siemens 6Bk1602-0Aa12-0Tp0_Firmware
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center