What happened
Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.
Affected versions
Bitbucket Server and Data Center: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 51040Bitbucket v7.0.0 - RCEkhal4n12023-03-23VerifiedPoC-in-GitHub · notdls/CVE-2022-36804A real exploit for BitBucket RCE CVE-2022-36804★ 35notdls2022-09-07CandidatePoC-in-GitHub · notxesh/CVE-2022-36804-PoCMultithreaded exploit script for CVE-2022-36804 affecting BitBucket versions <8.3.1★ 18notxesh2022-09-19CandidatePoC-in-GitHub · JRandomSage/CVE-2022-36804-MASS-RCEA critical vulnerability (CVE-2022-36804) in Atlassian Bitbucket Server and Data Center could be exploited by unauthorized attackers to execute malicious code on vulnerable instances.★ 0JRandomSage2022-09-20CandidatePoC-in-GitHub · benjaminhays/CVE-2022-36804-PoC-ExploitSomewhat Reliable PoC Exploit for CVE-2022-36804 (BitBucket Critical Command Injection)★ 16benjaminhays2022-09-20CandidatePoC-in-GitHub · Vulnmachines/bitbucket-cve-2022-36804CVE-2022-36804 Atlassian Bitbucket Command Injection Vulnerability★ 3Vulnmachines2022-09-20CandidatePoC-in-GitHub · kljunowsky/CVE-2022-36804-POCBitbucket CVE-2022-36804 unauthenticated remote command execution★ 7kljunowsky2022-09-21CandidatePoC-in-GitHub · Chocapikk/CVE-2022-36804-ReverseShellPoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)★ 4Chocapikk2022-09-23CandidatePoC-in-GitHub · khal4n1/CVE-2022-36804You can find a python script to exploit the vulnerability on Bitbucket related CVE-2022-36804.★ 3khal4n12022-09-24CandidatePoC-in-GitHub · 0xEleven/CVE-2022-36804-ReverseShellPoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)★ 00xEleven2022-09-24CandidatePoC-in-GitHub · tahtaciburak/cve-2022-36804A simple PoC for Atlassian Bitbucket RCE [CVE-2022-36804]★ 7tahtaciburak2022-09-25CandidatePoC-in-GitHub · sh4den/CVE-2022-36804A loader for bitbucket 2022 rce (cve-2022-36804)★ 12sh4den2022-09-26CandidatePoC-in-GitHub · ColdFusionX/CVE-2022-36804Atlassian Bitbucket Server and Data Center - Command Injection Vulnerability (CVE-2022-36804)★ 7ColdFusionX2022-10-04CandidatePoC-in-GitHub · devengpk/CVE-2022-36804★ 0devengpk2022-12-20CandidatePoC-in-GitHub · walnutsecurity/cve-2022-36804A critical command injection vulnerability was found in multiple API endpoints of the Atlassian Bit bucket Server and Data center. This vulnerability affects all versions of Bitbucket Server and Data Center released before versions <7.6.17, <7.17.10, <7.21.4, <8.0.3, <8.1.2, <8.2.2, and <8.3.1★ 8walnutsecurity2023-01-23CandidatePoC-in-GitHub · imbas007/Atlassian-Bitbucket-CVE-2022-36804★ 0imbas0072023-02-02CandidatePoC-in-GitHub · asepsaepdin/CVE-2022-36804★ 0asepsaepdin2025-01-30CandidatePoC-in-GitHub · DanielHallbro/CVE-2022-36804-Bitbucket-RCE-AnalysisFull-chain reproduction of CVE-2022-36804 (Bitbucket RCE). Includes a Dockerized laboratory, pspy64 monitoring for null-byte injection verification, and a custom Bash exploit script. Based on Assetnote research.★ 0DanielHallbro2026-02-26CandidatePoC-in-GitHub · JohanGabrielson/bitbucket-testInvestigating CVE-2022-36804★ 0JohanGabrielson2026-03-24CandidatePoC-in-GitHub · Junohea/cve-2022-36804CVE-2022-36804 Bitbucket command execution and file transfer tool★ 0Junohea2026-08-21CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.