Code Injection in Confluence Server and Jira Software Data Center - CVE-2022-26134
Published: June 3, 2022 / Updated: June 21, 2024
Vulnerability identifier: #VU63958
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26134
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper input validation when processing OGNL expressions. A remote non-authenticated attacker can send a specially crafted request to the Confluence Server and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.Affected software
Confluence Server
Jira Software Data Center
Jira Software Data Center
How to mitigate CVE-2022-26134
Install update from vendor's website.
Confluence Server - addressed in versions 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, 7.18.1
Links to Public Exploits and PoC-codes
- Exploit #10084 - CVE-2022-26134 (CVE-2022-26134 exploit script) (June 21, 2024)
- Exploit #8750 - CVE-2022-26134_check () (January 19, 2023)
- Exploit #8551 - cve_2022_26134 (Not the author of this script, reposting as original repo link is broken) (October 31, 2022)
- Exploit #8530 - CVE-2022-26134 () (October 25, 2022)
- Exploit #8496 - cve-2022-26134 (cve-2022-26134) (October 19, 2022)
- Exploit #8495 - CVE-2022-26134 (在受影响的Confluence Server 和Data Center 版本中,存在一个OGNL 注入漏洞,该漏洞允许未经身份验证的攻击者在Confluence Server 或Data Center 服务器上执行任意代码。) (October 19, 2022)
- Exploit #8480 - CVE-2022-26134 (Confluence Server and Data Center存在一个远程代码执行漏洞,未经身份验证的攻击者可以利用该漏洞向目标服务器注入恶意ONGL表达式,进而在目标服务器上执行任意代码。) (October 16, 2022)
- Exploit #8479 - CVE-2022-26134 (CVE-2022-26134) (October 16, 2022)
- Exploit #8478 - CVE-2022-26134 (CVE-2022-26134poc) (October 16, 2022)
- Exploit #8442 - CVE-2022-26134-miam () (October 4, 2022)
- Exploit #8279 - CVE-2022-26134-Console (CVE-2022-26134-Console) (August 22, 2022)
- Exploit #8167 - CVE-2022-26134 (远程攻击者在Confluence未经身份验证的情况下,可构造OGNL表达式进行注入,实现在Confluence Server或Data Center上执行任意代码,在现有脚本上修改了poc,方便getshell。) (July 24, 2022)
- Exploit #8147 - cve-2022-26134 (Just simple PoC for the Atlassian Jira exploit. Provides code execution for unauthorised user on a server.) (July 17, 2022)
- Exploit #8133 - confusploit (This is a python script that can be used with Shodan CLI to mass hunting Confluence Servers vulnerable to CVE-2022-26134) (July 13, 2022)
- Exploit #8128 - CVE-2022-26134 (confluence rce) (July 10, 2022)
- Exploit #8119 - CVE_2022_26134-detect () (July 6, 2022)
- Exploit #8117 - cve-2022-26134 () (July 6, 2022)
- Exploit #8115 - CVE-2022-26134 (Atlassian Confluence (CVE-2022-26134) - Unauthenticated Remote code execution (RCE)) (July 5, 2022)
- Exploit #8111 - CVE-2022-26134 (Atlassian Confluence (CVE-2022-26134) - Unauthenticated OGNL injection vulnerability (RCE).) (July 5, 2022)
- Exploit #8093 - CVE-2022-26134_conFLU (PoC for exploiting CVE-2022-26134 on Confluence) (June 29, 2022)
- Exploit #8075 - CVE-2022-26134 (Atlassian Confluence OGNL Injection Remote Code Execution (RCE) Vulnerability (CVE-2022-26134)) (June 24, 2022)
- Exploit #8061 - CVE-2022-26134 ([PoC] Atlassian Confluence (CVE-2022-26134) - Unauthenticated OGNL injection vulnerability (RCE)) (June 22, 2022)
- Exploit #8054 - CVE-2022-26134 (「?」CVE-2022-26134 - Confluence Pre-Auth RCE) (June 19, 2022)
- Exploit #8043 - Confluence Data Center 7.18.0 - Remote Code Execution (RCE) (June 15, 2022)
- Exploit #8036 - CVE-2022-26134-bis () (June 13, 2022)
- Exploit #8030 - CVE-2022-29464-bis () (June 13, 2022)
- Exploit #8025 - BotCon ([CVE-2022-26134] Attlasian Confluence RCE) (June 12, 2022)
- Exploit #8023 - CVE-2022-26134 () (June 12, 2022)
- Exploit #8021 - exploit_CVE-2022-26134 (CVE-2022-26134, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. This is CVE-2022-26134 expoitation script) (June 12, 2022)
- Exploit #8015 - CVE-2022-26134 (CVE-2022-26134) (June 9, 2022)
- Exploit #8004 - CVE-2022-26134 () (June 9, 2022)
- Exploit #8002 - ConfluentPwn (Atlassian confluence unauthenticated ONGL injection remote code execution scanner (CVE-2022-26134).) (June 9, 2022)
- Exploit #7994 - cve-2022-26134 (Implementation of CVE-2022-26134) (June 8, 2022)
- Exploit #7992 - CVE-2022-26134 (CVE-2022-26134 Confluence OGNL Injection POC) (June 8, 2022)
- Exploit #7991 - CVE-2022-26134 (Atlassian Confluence 远程代码执行漏洞(CVE-2022-26134)) (June 8, 2022)
- Exploit #7990 - CVE-2022-26134-Confluence-RCE (Exploit for CVE-2022-26134: Confluence Pre-Auth Remote Code Execution via OGNL Injection ) (June 8, 2022)
- Exploit #7986 - CVE-2022-26134-Confluence () (June 8, 2022)
- Exploit #7984 - CVE-2022-26134 (Atlassian Confluence- Unauthenticated OGNL injection vulnerability (RCE) ) (June 8, 2022)
- Exploit #7980 - CVE-2022-26134 () (June 6, 2022)
- Exploit #7977 - cve2022-26134exp (cve2022-26134) (June 6, 2022)
- Exploit #7974 - CVE-2022-26134 () (June 6, 2022)
- Exploit #7973 - Confluence-CVE-2022-26134 () (June 6, 2022)
- Exploit #7972 - CVE-2022-26134 ([CVE-2022-26134]Confluence OGNL expression injected RCE with sandbox bypass.) (June 6, 2022)
- Exploit #7970 - Serein (【懒人神器】一款图形化、批量采集url、批量对采集的url进行各种nday检测的工具。可用于src挖掘、cnvd挖掘、0day利用、打造自己的武器库等场景。可以批量利用Actively Exploited Atlassian Confluence 0Day CVE-2022-26134和DedeCMS v5.7.87 SQL注入 CVE-2022-23337。) (June 6, 2022)
- Exploit #7969 - CVE-2022-26134 (Confluence Server and Data Center - CVE-2022-26134 - Critical severity unauthenticated remote code execution vulnerability PoC) (June 6, 2022)
- Exploit #7967 - CVE-2022-26134 (CVE-2022-26134 - Atlassian Confluence unauthenticated OGNL injection vulnerability (RCE).) (June 6, 2022)
- Exploit #7966 - CVE-2022-26134 (Atlassian confluence poc) (June 6, 2022)
- Exploit #7965 - CVE-2022-26134 () (June 6, 2022)
- Exploit #7964 - CVE-2022-26134 () (June 6, 2022)
- Exploit #7963 - Confluence-CVE-2022-26134 (CVE-2022-26134) (June 6, 2022)
- Exploit #7962 - through_the_wire (CVE-2022-26134 Proof of Concept) (June 6, 2022)
- Exploit #7961 - CVE-2022-26134 ((CVE-2022-26134)an unauthenticated and remote OGNL injection vulnerability resulting in code execution in the context of the Confluence server) (June 6, 2022)
- Exploit #7960 - CVE_2022_26134-detect () (June 6, 2022)
- Exploit #7959 - CVE-2022-26134 (Confluence Pre-Auth Remote Code Execution via OGNL Injection (CVE-2022-26134)) (June 6, 2022)
- Exploit #7958 - CVE-2022-26134 (CVE-2022-26134 - Confluence Pre-Auth RCE | OGNL injection) (June 6, 2022)