CVE-2023-22515
Published Oct 4, 2023
Last updated 3 months ago
- Description
- Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
- Source
- security@atlassian.com
- NVD status
- Analyzed
- Products
- confluence_data_center, confluence_server
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 3.0
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
- Exploit added on
- Oct 5, 2023
- Exploit action due
- Oct 13, 2023
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA.
- nvd@nist.gov
- NVD-CWE-noinfo
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-20
- Hype score
- Not currently trending
I just completed Confluence CVE-2023-22515 room on TryHackMe! Exploit CVE-2023-22515 to get admin access to Confluence Server and Data Center editions. https://t.co/Qe5LIyD9L7 #tryhackme via @tryhackme #tryhackme #Consistency #cyberverse #vulnerability
@LittleSun4lower
19 Apr 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2023-22515 is a CVSS 9.8 Atlassian Confluence zero-day that lets unauthenticated attackers create admin accounts in three HTTP requests — exploited by Chinese APT Storm-0062 for 20 days before the patch existed. https://t.co/Chm9mIbg3C
@vulnsurge
26 Mar 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
I just completed Confluence CVE-2023-22515 room on TryHackMe! Exploit CVE-2023-22515 to get admin access to Confluence Server and Data Center editions. https://t.co/7trslcTTWC #tryhackme via @tryhackme
@ToTo13ru_xakep
10 Mar 2026
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Day 58/365 tryhackme I just completed Confluence CVE-2023-22515 room on TryHackMe! Exploit CVE-2023-22515 to get admin access to Confluence Server and Data Center editions. https://t.co/q5UfuyXZdy?
@purpullgirl
28 Feb 2026
88 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
I just completed Confluence CVE-2023-22515 room on TryHackMe! Exploit CVE-2023-22515 to get admin access to Confluence Server and Data Center editions. https://t.co/q6WoeMnHZO #tryhackme через @tryhackme
@mrBr4un
23 Feb 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Confluence 0-day: setup grants admin access Concise incident summary: CVE-2023-22515 in Atlassian Confluence enables unauthenticated users to force Setup Mode, create a persistent admin account, and complete setup, gaining full control. Exploited via curl to /setup/*; urgent
@Secwiserapp
16 Feb 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Day 84 of #100DaysOfCybersecurity🛡️ Confluence CVE-2023-22515 lab completed 📷✅ • CVSS 10.0 broken access control flaw 🔥 • Reenables initial setup remotely • Create a new admin with zero auth • Full takeover in one request Actively exploited in the wild ⚠️
@HezyChacha
5 Jan 2026
70 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
I just completed Confluence CVE-2023-22515 room on TryHackMe! Exploit CVE-2023-22515 to get admin access to Confluence Server and Data Center editions. https://t.co/pKFQoJ4lev #tryhackme via @tryhackme
@HezyChacha
5 Jan 2026
51 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2023-22515 – Confluence Broken Access Control Exploit This script is designed to exploit the CVE-2023-22515 vulnerability in Confluence, which allows for unauthorized access to Confluence Server and Confluence Data Center instances. The vulnerability is categorized as a
@HackingTeam777
15 Nov 2025
647 Impressions
0 Retweets
5 Likes
1 Bookmark
0 Replies
0 Quotes
GitHub - Chocapikk/CVE-2023-22515: CVE-2023-22515: Confluence Broken Access Control Exploit https://t.co/SZyC4zC5qk
@akaclandestine
14 Nov 2025
902 Impressions
5 Retweets
15 Likes
6 Bookmarks
0 Replies
0 Quotes
I just completed Confluence CVE-2023-22515 room on TryHackMe. Exploit CVE-2023-22515 to get admin access to Confluence Server and Data Center editions. https://t.co/FGR2AqY6xR #tryhackme 来自 @realtryhackme
@GuanShanZhe
14 Oct 2025
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CRITICAL CONFLUENCE FLAW! A Broken Access Control (CVE-2023-22515) vulnerability grants attackers Unauthorized Access to Internal Data. Your internal documentation, knowledge base, and secrets are exposed. Read the full report on - https://t.co/IBex3VuWTb https://t.co/lV12ZmaY3Q
@cyberbivash
30 Sept 2025
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
I just completed Confluence CVE-2023-22515 room on TryHackMe. Exploit CVE-2023-22515 to get admin access to Confluence Server and Data Center editions. https://t.co/a6TM8wNkKl #tryhackme via @realtryhackme
@buttbundy
31 Aug 2025
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
对 Confluence CVE-2023-22515 的一点分析 漏洞通告分析 由漏洞通告可以定位到 /setup/* 系列路由,刚开始以为直接访问 /setup/setupadministrator.action 添加管理员就行,当搭好环境进行测试时 Dns域名劫持,拖库,外挂等业务
@hacker_HouZi
7 Aug 2025
1035 Impressions
0 Retweets
16 Likes
0 Bookmarks
0 Replies
0 Quotes
对 Confluence CVE-2023-22515 的一点分析 漏洞通告分析 由漏洞通告可以定位到 /setup/* 系列路由,刚开始以为直接访问 /setup/setupadministrator.action 添加管理员就行,当搭好环境进行测试时 Dns域名劫持,拖库,外挂等业务
@hacker_HouZi
17 Jul 2025
1311 Impressions
0 Retweets
10 Likes
0 Bookmarks
0 Replies
0 Quotes
Adamlar CVE-2023-22515’den yararlanıp, İSO dosyasında truva yürütüyor. Siz ısrarla kali kurmaya çalışıyorsunuz🤔
@alpagu995
18 Dec 2024
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
"matchCriteriaId": "85B2AD9F-CBA6-4559-9AE3-5F76A9EC3B7F",
"versionEndExcluding": "8.3.3",
"versionStartIncluding": "8.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
"matchCriteriaId": "38F9918D-6848-4CD6-8096-4FB48C23818B",
"versionEndExcluding": "8.4.3",
"versionStartIncluding": "8.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8D646BCF-214F-449D-AEEB-B253E8715394",
"versionEndExcluding": "8.5.2",
"versionStartIncluding": "8.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "970A3DA7-5114-4696-A93D-C3D5AFF5C6C5",
"versionEndExcluding": "8.3.3",
"versionStartIncluding": "8.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A2EB19CD-AE29-4775-91C5-05B01A96AC6C",
"versionEndExcluding": "8.4.3",
"versionStartIncluding": "8.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "79229BE7-0AA0-4308-8BB2-8FB11E8B9AD7",
"versionEndExcluding": "8.5.2",
"versionStartIncluding": "8.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]