CVE-2022-26138
KEVCRITICAL 9.8EPSS 98.2%
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 98.17% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-07-29
- Nuclei
- critical · CWE-798
- Published
- 2022-07-20
- Updated
- 2026-01-12
Proof-of-concept exploits (4)
- Vulnmachines/Confluence-Question-CVE-2022-26138-3★ · 2022-07-28
- alcaparra/CVE-2022-2613831★ · 2022-07-26
- shavchen/CVE-2022-261380★ · 2022-07-22
- z92g/CVE-2022-2613815★ · 2022-07-30