CVE-2023-22515

critical

Description

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

From the Tenable Blog

CVE-2023-22515: Zero-Day Vulnerability in Atlassian Confluence Data Center and Server Exploited in the Wild
CVE-2023-22515: Zero-Day Vulnerability in Atlassian Confluence Data Center and Server Exploited in the Wild

Published: 2023-10-04

A critical zero-day vulnerability in Atlassian Confluence Data Center and Server has been exploited in the wild in a limited number of cases. Organizations should patch or apply the mitigation steps as soon as possible.

References

https://github.com/Balckers/mcp-security-server

https://github.com/chengbochuan3/CVE-Confluence

https://github.com/HaakimSec/zero2shell-50

https://github.com/panda12332145/cve-vulnerability-scanner

https://github.com/nguyenminhduc3103/CVE_TOOL_SIGMARULE

https://github.com/dkq-k/cve-2023-22515-1

https://github.com/dkq-k/CVE-2023-22515

https://github.com/Lad1411/CVEs-matching

https://github.com/radzek15/CVE-2023-22515

https://github.com/CyberSentinel321/cve-2023-22515-lab

https://github.com/Arkha-Corvus/LetsDefend-SOC235-Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515-EventID-197

https://github.com/V0idA2tronaut/CVEs

https://github.com/odaysec/confluPwn

https://github.com/imthenachoman/How-To-Secure-A-Linux-Server

https://github.com/vivigotnotime/CVE-2023-22515-Exploit-Script

https://github.com/zgimszhd61/CVE-2023-22518

https://github.com/kh4sh3i/CVE-2023-22527

https://github.com/Onedy1703/CVE-2023-22515

https://github.com/spareack/CVE-2023-22515-NSE

https://github.com/xorbbo/cve-2023-22515

https://github.com/rxerium/CVE-2023-22515

https://github.com/Lotus6/ConfluenceMemshell

https://github.com/yoryio/CVE-2023-22527

https://github.com/CalegariMindSec/Exploit-CVE-2023-22515

https://github.com/C1ph3rX13/CVE-2023-22518

https://github.com/aaaademo/Confluence-EvilJar

https://github.com/LucasPDiniz/CVE-2023-22515

https://github.com/davidfortytwo/CVE-2023-22518

https://github.com/AIex-3/confluence-hack

https://github.com/C1ph3rX13/CVE-2023-22515

https://github.com/joaoviictorti/CVE-2023-22515

https://github.com/iveresk/CVE-2023-22515

https://github.com/ad-calcium/CVE-2023-22515

https://github.com/Chocapikk/CVE-2023-22515

https://github.com/r4p70rs/CVE-2023-22515-PoC

https://github.com/ErikWynter/CVE-2023-22515-Scan

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22515

https://jira.atlassian.com/browse/CONFSERVER-92475

https://confluence.atlassian.com/pages/viewpage.action?pageId=1295682276

https://confluence.atlassian.com/display/KB/FAQ+for+CVE-2023-22515

http://packetstormsecurity.com/files/175225/Atlassian-Confluence-Unauthenticated-Remote-Code-Execution.html

Details

Source: Mitre, NVD

Published: 2023-10-04

Updated: 2026-06-17

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99156

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability of Interest