CVE-2022-26134
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- February 25, 2022
- Published Date
- June 03, 2022
- Last Updated
- February 04, 2025
- Vendor
- Atlassian
- Product
- Confluence Data Center, Confluence Server
- Description
- In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-06-02 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/atlassian_confluence_namespace_ognl_injection.rb | 2025-04-29 11:01:20 UTC |
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-26134.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
atlassian_confluence_namespace_ognl_injection
Type: metasploit • Created: Unknown
MaskCyberSecurityTeam/CVE-2022-26134_Behinder_MemShell
Type: github • Created: 2023-02-04 06:51:47 UTC • Stars: 9
cbk914/CVE-2022-26134_check
Type: github • Created: 2023-01-15 20:11:27 UTC • Stars: 3
wjlin0/CVE-2022-26134
Type: github • Created: 2022-12-25 15:29:14 UTC • Stars: 0
b4dboy17/CVE-2022-26134
Type: github • Created: 2022-10-24 19:00:25 UTC • Stars: 2
yigexioabai/CVE-2022-26134-cve1
Type: github • Created: 2022-10-15 06:01:53 UTC • Stars: 0
skhalsa-sigsci/CVE-2022-26134-LAB
Type: github • Created: 2022-10-09 17:15:07 UTC • Stars: 3
shiftsansan/CVE-2022-26134-Console
Type: github • Created: 2022-08-22 09:40:43 UTC • Stars: 0
keven1z/CVE-2022-26134
Type: github • Created: 2022-07-23 14:38:11 UTC • Stars: 7
twoning/CVE-2022-26134-PoC
Type: github • Created: 2022-07-14 01:28:16 UTC • Stars: 2
coskper-papa/CVE-2022-26134
Type: github • Created: 2022-07-08 12:24:21 UTC • Stars: 1
Debajyoti0-0/CVE-2022-26134
Type: github • Created: 2022-07-05 07:04:50 UTC • Stars: 2
nxtexploit/CVE-2022-26134
Type: github • Created: 2022-07-05 04:30:42 UTC • Stars: 26
ColdFusionX/CVE-2022-26134
Type: github • Created: 2022-06-24 10:33:13 UTC • Stars: 2
kh4sh3i/CVE-2022-26134
Type: github • Created: 2022-06-21 11:49:48 UTC • Stars: 4
AmoloHT/CVE-2022-26134
Type: github • Created: 2022-06-19 13:50:22 UTC • Stars: 14
Chocapikk/CVE-2022-26134
Type: github • Created: 2022-06-13 23:01:39 UTC • Stars: 4
murataydemir/CVE-2022-26134
Type: github • Created: 2022-06-10 09:52:22 UTC • Stars: 1
cai-niao98/CVE-2022-26134
Type: github • Created: 2022-06-09 02:11:58 UTC • Stars: 3
Y000o/Confluence-CVE-2022-26134
Type: github • Created: 2022-06-07 16:42:36 UTC • Stars: 4
whokilleddb/CVE-2022-26134-Confluence-RCE
Type: github • Created: 2022-06-07 11:17:25 UTC • Stars: 12
alcaparra/CVE-2022-26134
Type: github • Created: 2022-06-07 10:36:11 UTC • Stars: 4
BeichenDream/CVE-2022-26134-Godzilla-MEMSHELL
Type: github • Created: 2022-06-07 09:19:02 UTC • Stars: 337
li8u99/CVE-2022-26134
Type: github • Created: 2022-06-07 06:57:02 UTC • Stars: 4
CatAnnaDev/CVE-2022-26134
Type: github • Created: 2022-06-06 16:45:35 UTC • Stars: 3
archanchoudhury/Confluence-CVE-2022-26134
Type: github • Created: 2022-06-06 06:16:47 UTC • Stars: 4
hev0x/CVE-2022-26134
Type: github • Created: 2022-06-06 02:43:06 UTC • Stars: 40
abhishekmorla/CVE-2022-26134
Type: github • Created: 2022-06-05 20:35:38 UTC • Stars: 10
Vulnmachines/Confluence-CVE-2022-26134
Type: github • Created: 2022-06-05 12:23:34 UTC • Stars: 3
SNCKER/CVE-2022-26134
Type: github • Created: 2022-06-04 11:16:28 UTC • Stars: 28
shamo0/CVE-2022-26134
Type: github • Created: 2022-06-04 10:44:38 UTC • Stars: 1
Brucetg/CVE-2022-26134
Type: github • Created: 2022-06-04 10:27:50 UTC • Stars: 2
kyxiaxiang/CVE-2022-26134
Type: github • Created: 2022-06-04 05:46:48 UTC • Stars: 3
crowsec-edtech/CVE-2022-26134
Type: github • Created: 2022-06-03 19:24:30 UTC • Stars: 32
offlinehoster/CVE-2022-26134
Type: github • Created: 2022-06-03 08:01:49 UTC • Stars: 8