CVE-2022-26138
Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
- Published
- Jul 20, 2022
- Updated
- Jan 12, 2026
- Assigning CNA
- atlassian
- Evidence observed
- Jul 29, 2022
Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.
Exploit for CVE-2022-26138, a SAML SSO bypass vulnerability in Atlassian products, with a FOFA dork for identifying vulnerable instances.
Atlassian Questions Hardcoded Password (CVE-2022-26138)
Atlassian Confluence Server and Data Center: CVE-2022-26138
Confluence Hardcoded Password POC
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.