Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
Atlassian — Confluence Data Center
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
9.8
100.0%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- Oct 31, 2023
- Modified
- Jun 17, 2026
- Added to KEV
- Nov 7, 2023
- Federal patch due
- Nov 28, 2023
CISA required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2023-22518, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- ForceFledgling/CVE-2023-22518★ 61
Improper Authorization Vulnerability in Confluence Data Center and Server
updated Apr 6, 2026
- RevoltSecurities/CVE-2023-22518★ 43
An Exploitation tool to exploit the confluence server that are vulnerable to CVE-2023-22518 Improper Authorization
updated Aug 15, 2025
- davidfortytwo/CVE-2023-22518★ 8
Checker for CVE-2023-22518 vulnerability on Confluence
updated May 17, 2024
- 0x0d3ad/CVE-2023-22518★ 5
Exploit CVE-2023-22518
updated Aug 28, 2024
- 0x00sector/CVE_2023_22518_Checker★ 3
CVE_2023_22518_Checker
updated Dec 31, 2023
- bibo318/CVE-2023-22518★ 1
Lỗ hổng ủy quyền không phù hợp trong Trung tâm dữ liệu Confluence và Máy chủ + bugsBonus 🔥
updated Jan 24, 2024
- Lilly-dox/Exploit-CVE-2023-22518★ 1
updated Mar 22, 2024
- d3ckkNo0b/analyze-Exploit-CVE-2023-22518-Confluence★ 1
updated May 5, 2025
References
Frequently asked questions
What is CVE-2023-22518?
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
How severe is CVE-2023-22518?
CVE-2023-22518 has a CVSS base score of 9.8 out of 10 (CVSS 3.1).
Is CVE-2023-22518 actively exploited in the wild?
Yes. CVE-2023-22518 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Nov 7, 2023, meaning CISA has confirmed evidence of active exploitation. It is also flagged as used in ransomware campaigns.
What is the EPSS score for CVE-2023-22518?
100.0% - meaning FIRST.org's EPSS model estimates a 100.0% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2023-22518?
Yes - a public Nuclei template referencing CVE-2023-22518 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2023-22518?
CVE-2023-22518 is classified under CWE-863 (CWE-863 Incorrect Authorization).
Cross-checked against
Impactr finds and proves whether CVE-2023-22518 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist