Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability
Atlassian — Confluence Data Center
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.
9.8
100.0%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- Jun 3, 2022
- Modified
- Jun 17, 2026
- Added to KEV
- Jun 2, 2022
- Federal patch due
- Jun 6, 2022
CISA required action
Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2022-26134, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- W01fh4cker/Serein★ 1249
【懒人神器】一款图形化、批量采集url、批量对采集的url进行各种nday检测的工具。可用于src挖掘、cnvd挖掘、0day利用、打造自己的武器库等场景。可以批量利用Actively Exploited Atlassian Confluence 0Day CVE-2022-26134和DedeCMS v5.7.87 SQL注入 CVE-2022-23337。
updated Sep 4, 2026
- BeichenDream/CVE-2022-26134-Godzilla-MEMSHELL★ 340
updated Jul 23, 2026
- jbaines-r7/through_the_wire★ 173
CVE-2022-26134 Proof of Concept
updated Jul 24, 2026
- hev0x/CVE-2022-26134★ 44
Confluence Pre-Auth Remote Code Execution via OGNL Injection (CVE-2022-26134)
updated Mar 18, 2026
- 0x14dli/cve2022-26134exp★ 37
cve2022-26134
updated Mar 5, 2026
- crowsec-edtech/CVE-2022-26134★ 31
CVE-2022-26134 - Confluence Pre-Auth RCE | OGNL injection
updated Aug 20, 2026
- nxtexploit/CVE-2022-26134★ 29
Atlassian Confluence (CVE-2022-26134) - Unauthenticated Remote code execution (RCE)
updated Mar 18, 2026
- SNCKER/CVE-2022-26134★ 26
[CVE-2022-26134]Confluence OGNL expression injected RCE with sandbox bypass.
updated Jul 31, 2026
References
Frequently asked questions
What is CVE-2022-26134?
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.
How severe is CVE-2022-26134?
CVE-2022-26134 has a CVSS base score of 9.8 out of 10 (CVSS 3.1).
Is CVE-2022-26134 actively exploited in the wild?
Yes. CVE-2022-26134 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Jun 2, 2022, meaning CISA has confirmed evidence of active exploitation. It is also flagged as used in ransomware campaigns.
What is the EPSS score for CVE-2022-26134?
100.0% - meaning FIRST.org's EPSS model estimates a 100.0% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2022-26134?
Yes - a public Nuclei template referencing CVE-2022-26134 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2022-26134?
CVE-2022-26134 is classified under CWE-917 (CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')).
Cross-checked against
Impactr finds and proves whether CVE-2022-26134 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist