What happened
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.
Affected versions
Confluence Data Center and Server: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
SploitusCritical vulnerability in Atlassian Confluence (CVE-2023-22518) allowing admin account creation.KitPloit2026-08-28T10:02:13Candidatekitploit.comCritical vulnerability in Atlassian Confluence (CVE-2023-22518) allowing admin account creation.hi2026-08-28T10:02:13CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.