CVE-2022-26134: Atlassian Confluence OGNL RCE
An unauthenticated remote code execution vulnerability in Atlassian Confluence Server and Data Center, caused by an OGNL expression injection reachable through crafted request URIs. It was exploited in the wild as a zero-day before a patch existed, letting attackers run arbitrary commands on internet-facing Confluence instances with no credentials.
View the authoritative record on NVD ↗Affected software
- Confluence Server and Data Center releases prior to 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, and 7.18.1
How it's exploited
Send an unauthenticated HTTP request with an OGNL expression embedded in the URI path; Confluence's request-handling pipeline evaluates the expression before authentication is checked, giving the attacker arbitrary command execution on the underlying server.
Severity
CVE-2022-26134 carries a CVSS 3.1 base score of 9.8, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2022-26134 is categorized under CWE-917, CWE-74, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Upgrade to a fixed Confluence version per Atlassian's advisory immediately; if patching must wait, apply the documented temporary WAF/network mitigations and treat any internet-facing instance running an affected version as potentially already compromised.
Frequently asked questions
What is CVE-2022-26134?
An unauthenticated remote code execution vulnerability in Atlassian Confluence Server and Data Center, caused by an OGNL expression injection reachable through crafted request URIs. It was exploited in the wild as a zero-day before a patch existed, letting attackers run arbitrary commands on internet-facing Confluence instances with no credentials.
How severe is CVE-2022-26134?
CVE-2022-26134 has a CVSS 3.1 base score of 9.8 out of 10, rated Critical.
What software is affected by CVE-2022-26134?
CVE-2022-26134 affects Confluence Server and Data Center releases prior to 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, and 7.18.1.
How do you fix CVE-2022-26134?
Upgrade to a fixed Confluence version per Atlassian's advisory immediately; if patching must wait, apply the documented temporary WAF/network mitigations and treat any internet-facing instance running an affected version as potentially already compromised.
Where is the authoritative record for CVE-2022-26134?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2022-26134 at https://nvd.nist.gov/vuln/detail/CVE-2022-26134, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest