Back to Labs
Security Advisory

CVE-2023-22518

About

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability.

Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

Weakness (CWE):CWE-863

Rainforest analyst review

This is an improper-authorization flaw in Confluence Data Center and Server that exposes a setup/restore path to unauthenticated users. By reaching it, an attacker can reset the Confluence instance and create a fresh administrator account, then use that account to perform any administrative action. It is not memory corruption or injection; it is a missing authorization check on a powerful function, and the outcome is full control of the instance with total loss of confidentiality, integrity, and availability. Atlassian Cloud sites are not affected.

Confluence is a corporate knowledge base, routinely holding internal documentation, credentials, architecture notes, and other sensitive material, and self-hosted instances are often internet-reachable. Atlassian escalated the severity after observing active exploitation, and ransomware operators, including Cerber, moved on vulnerable servers within days; it sits on CISA's KEV list. Upgrade to a fixed version at once. Given how fast this was weaponized, assume an exposed server may already be compromised: pull it off the internet if you cannot patch immediately, then hunt for unexpected admin accounts, and treat data reset or exfiltration as a live possibility rather than a hypothetical.

References

Related CVEs

Frequently asked questions

What is CVE-2023-22518?

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account.

How severe is CVE-2023-22518?

CVE-2023-22518 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2023-22518 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2023-22518?

Public advisories list the following as affected: confluence data center, confluence server. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2023-22518?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email