← Back to browse · API

CVE-2022-26138

Severity
CRITICAL
CVSS
9.8
EPSS
0.9817
Risk score
59.36
CISA KEV
Yes
PoC
No
Published
2022-07-20
Modified
2026-01-12
First seen
2026-08-07
Aliases
EUVD-2022-30705, GHSA-23XF-WG9R-49FR
Products
Atlassian:Confluence, Atlassian:Questions For Confluence 2.7.34, Atlassian:Questions For Confluence 2.7.35, Atlassian:Questions For Confluence 3.0.2
Sources
cisa.gov CVE-2022-26138
euvd EUVD-2022-30705

Description

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

References