CVE-2022-26134
KEV RANSOMWARECRITICAL 9.8EPSS 100.0%
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-06-02, used in ransomware campaigns
- Nuclei
- critical · CWE-917
- Published
- 2022-06-03
- Updated
- 2025-10-21
Proof-of-concept exploits (92)
- http://packetstormsecurity.com/files/167430/Confluence-OGNL-Injection-Remote-Code-Executi…
- http://packetstormsecurity.com/files/167431/Through-The-Wire-CVE-2022-26134-Confluence-Pr…
- http://packetstormsecurity.com/files/167432/Confluence-OGNL-Injection-Proof-Of-Concept.ht…
- http://packetstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGNL-Injection…
- 0x14dli/cve2022-26134exp37★ · 2022-08-03
- 0xAgun/CVE-2022-261341★ · 2022-06-06
- 0xNslabs/CVE-2022-36553-PoC6★ · 2024-01-08
- 1337in/CVE-2022-26134web1★ · 2022-08-26
- 2212970396/CVE_2022_261340★ · 2022-07-14
- 24-2021/EXP-POC26★ · 2023-01-11
- 404fu/CVE-2022-26134-POC1★ · 2024-03-26
- Agentgilspy/CVE-2022-261340★ · 2024-11-17
- AmoloHT/CVE-2022-2613414★ · 2022-06-19
- BeichenDream/CVE-2022-26134-Godzilla-MEMSHELL340★ · 2022-06-07
- Brucetg/CVE-2022-261342★ · 2022-06-05
- CJ-0107/cve-2022-261341★ · 2022-10-16
- Chocapikk/CVE-2022-261344★ · 2022-10-19
- ColdFusionX/CVE-2022-261342★ · 2022-06-24
- Debajyoti0-0/CVE-2022-261343★ · 2022-07-05
- ExpLangcn/HVVExploitApply_POC19★ · 2022-08-25
- Gilospy/CVE-2022-261340★ · 2024-11-17
- Habib0x0/CVE-2022-261341★ · 2022-06-07
- Khalidhaimur/CVE-2022-261340★ · 2025-02-12
- Luchoane/CVE-2022-26134_conFLU0★ · 2022-07-01
- MAHABUB122003/Atlassian-CVE-2022-261340★ · 2025-06-14
- MaskCyberSecurityTeam/CVE-2022-26134_Behinder_MemShell9★ · 2023-02-04
- Muhammad-Ali007/Atlassian_CVE-2022-261340★ · 2023-08-03
- SNCKER/CVE-2022-2613426★ · 2022-06-18
- Vulnmachines/Confluence-CVE-2022-261343★ · 2022-07-13
- Y000o/Confluence-CVE-2022-261344★ · 2022-06-07
- abhishekmorla/CVE-2022-261348★ · 2022-06-08
- acfirthh/CVE-2022-261341★ · 2023-09-20
- alcaparra/CVE-2022-261344★ · 2022-06-07
- archanchoudhury/Confluence-CVE-2022-261344★ · 2022-06-10
- axingde/CVE-2022-261341★ · 2022-06-05
- b4dboy17/CVE-2022-261342★ · 2022-10-24
- badboy-sft/CVE-2022-261342★ · 2022-10-24
- cai-niao98/CVE-2022-261343★ · 2022-06-09
- cc3305/CVE-2022-261340★ · 2024-07-27
- chaosec2021/EXP-POC26★ · 2023-01-11
- coskper-papa/CVE-2022-261341★ · 2022-07-08
- crowsec-edtech/CVE-2022-2613431★ · 2022-06-03
- f4yd4-s3c/cve-2022-261342★ · 2025-05-23
- h3v0x/CVE-2022-2613444★ · 2022-06-06
- hab1b0x/CVE-2022-261341★ · 2022-06-07
- hev0x/CVE-2022-2613444★ · 2022-06-06
- itwestend/cve_2022_261340★ · 2022-10-29
- iveresk/cve-2022-2613412★ · 2022-07-21
- jbaines-r7/through_the_wire173★ · 2022-06-06
- kailing0220/CVE-2022-261341★ · 2022-10-15
- kelemaoya/CVE-2022-261341★ · 2022-10-16
- keven1z/CVE-2022-261347★ · 2022-07-25
- keven1z/redTeamGadget6★ · 2022-08-01
- kh4sh3i/CVE-2022-261344★ · 2022-06-21
- kyxiaxiang/CVE-2022-261343★ · 2022-06-04
- latings/CVE-2022-261340★ · 2022-10-16
- li8u99/CVE-2022-261344★ · 2022-06-30
- ma1am/CVE-2022-26134-Exploit-Detection1★ · 2022-06-06
- mamba-2021/EXP-POC26★ · 2023-01-11
- mr-won/cve-2022-261340★ · 2025-03-30
- murataydemir/CVE-2022-261341★ · 2022-06-14
- nxtexploit/CVE-2022-2613429★ · 2024-08-23
- offlinehoster/CVE-2022-261348★ · 2022-06-03
- r1skkam/TryHackMe-Atlassian-CVE-2022-261341★ · 2022-07-04
- reubensammut/cve-2022-261341★ · 2022-06-07
- shamo0/CVE-2022-261341★ · 2022-06-04
- shiftsansan/CVE-2022-26134-Console0★ · 2022-08-23
- sunny-kathuria/exploit_CVE-2022-261340★ · 2022-06-10
- th3b3ginn3r/CVE-2022-26134-Exploit-Detection1★ · 2022-06-06
- thetowsif/CVE-2022-261340★ · 2025-06-09
- tpdlshdmlrkfmcla/cve-2022-261340★ · 2025-03-30
- twoning/CVE-2022-26134-PoC2★ · 2022-07-14
- vesperp/CVE-2022-26134-Confluence0★ · 2022-06-07
- whokilleddb/CVE-2022-26134-Confluence-RCE13★ · 2022-07-24
- wjlin0/CVE-2022-261340★ · 2022-12-26
- xsxtw/CVE-2022-261340★ · 2024-05-02
- yTxZx/CVE-2022-261340★ · 2023-10-20
- yigexioabai/CVE-2022-26134-cve10★ · 2022-10-15
- yyqxi/CVE-2022-261340★ · 2022-10-16
- crypt0lith/confluence-ognl-rce
- roodhelios/CVE-2022-26134-OGNL-Injection
- secjia/CVE-2022-26134
- 34zY/APT-Backpack
- CLincat/vulcat
- DataDog/security-labs-pocs
- chengbochuan3/CVE-Confluence
- demining/Log4j-Vulnerability
- iluaster/getdrive_PoC
- light0921/webscanner
- onewinner/VulToolsKit
- reph0r/poc-exp
- webdev11-code/shell-injection