CVE-2023-22518

CVE-2023-22518 is a critical-severity vulnerability in Atlassian Confluence Data Center with a CVSS 3.x base score of 9.8. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2023-11-07). The underlying weakness is classified as CWE-863.

Key facts

Description

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability.  Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

Frequently asked questions

What is CVE-2023-22518?
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability.  Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
How severe is CVE-2023-22518?
CVE-2023-22518 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
Is CVE-2023-22518 being actively exploited?
Yes. CVE-2023-22518 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2023-11-07, which means active exploitation has been confirmed. It should be prioritised for remediation.
What products are affected by CVE-2023-22518?
CVE-2023-22518 primarily affects Atlassian Confluence Data Center. In total, 4 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
How do I fix CVE-2023-22518?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
Does CVE-2023-22518 have an EU (EUVD) identifier?
Yes. CVE-2023-22518 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2023-26658. It is also flagged as exploited in the EUVD (since 2023-11-07).
When was CVE-2023-22518 published?
CVE-2023-22518 was published on 2023-10-31 and last updated on 2026-06-17.

References

Affected products (4)

More vulnerabilities in Atlassian Confluence Data Center

All CVEs affecting Atlassian Confluence Data Center →

Other CWE-863 (Incorrect Authorization) vulnerabilities

Browse all CWE-863 (Incorrect Authorization) vulnerabilities →