critical Known exploitedREV. 01

CVE-2022-26134Confluence Server & Data Center — Unauthenticated OGNL Injection RCE

Confluence Server and Data Center evaluate attacker-supplied text from the request path as program code, so an unauthenticated visitor can run arbitrary commands on the wiki server with a single crafted request.

YOUR NEXT MOVE

Update Confluence to 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4 or 7.18.1; block internet traffic to the instance until the update is deployed.

Read the risk

THE VITAL STATS
CVSS score
9.8/ 10
CVSS v3.1
EPSS probability
100%
Likelihood of exploitation
Attack complexity
Low
Conditions needed to exploit
Known exploited
Yes — CISA KEV
CVE published
2022-06-03
Added to KEV
2022-06-02
Exploit published
Yes
Confidence
high
Kill chain
initial access
MITRE ATT&CK
T1190
Severity
critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attacker needsNetwork access to a self-hosted Confluence instance. No credentials needed.

Fixed inConfluence 7.4.17, Confluence 7.13.7, Confluence 7.14.3, Confluence 7.15.2, Confluence 7.16.4, Confluence 7.17.4, Confluence 7.18.1

Behind the card

4 REFERENCES
Field-level provenanceTRACE THE SOURCES +

Which source supports each field, when it was retrieved, and who extracted it.

FieldsSourceRetrievedExtractorConfidence
title, summary, cvss, severity, exploitation.attack_complexity, exploitation.prerequisites, exploitation.exploit_available, remediation, referencesnvd.nist.gov2026-08-07claude-codehigh
exploitation.known_exploited, recommended_actioncisa.gov2026-08-07claude-codehigh
epssapi.first.org2026-08-07claude-codehigh

Printing history

THE RECORD
  1. r1Initial base card

First printing. This card has not been reprinted since publication.

crds:cve-2022-26134 · CRDS 0.1 · Issued 2026-08-07