Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-26138


The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.


Published

2022-07-20T18:15:08.617

Last Modified

2025-02-19T19:48:00.467

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-798
  • Type: Primary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application atlassian questions_for_confluence 2.7.34 Yes
Application atlassian questions_for_confluence 2.7.35 Yes
Application atlassian questions_for_confluence 3.0.2 Yes
Application atlassian confluence_data_center - No
Application atlassian confluence_server - No

References