CVE-2023-22515Active Exploitation(atlassian / confluence_data_center)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for atlassian confluence_data_center systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-10-13. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA.

Weakness type (CWE)
CWE-20

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • confluence_data_center
  • confluence_server

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Peaked 5d ago at 1 mentions (2026-02-16); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
confluence_data_centerconfluence_server

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-02-16: 1Mentions · 2026-02-23: 1Mentions · 2026-02-28: 1Mentions · 2026-03-10: 1Mentions · 2026-04-19: 1Mentions · 2026-06-17: 1PoC Mentioned / Linked · 2026-02-28: 1Active Exploitation · 2026-02-16: 1Active Exploitation · 2026-06-17: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-23: 1Technical Details · 2026-03-10: 102-1602-2302-2803-1004-1906-17
Signal classification4 categories
Active Exploitation
233.3%
PoC
233.3%
Exploit
116.7%
General
116.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-161
Active Exploitation1
2026-02-231
Exploit1
2026-02-281
PoC1
2026-03-101
General1
2026-04-191
PoC1
2026-06-171
Active Exploitation1
Full discourse6 posts
  • Orifha Joan@purpullgirl
    PoC

    Day 58/365 tryhackme I just completed Confluence CVE-2023-22515 room on TryHackMe! Exploit CVE-2023-22515 to get admin access to Confluence Server and Data Center editions. https://tryhackme.com/room/confluence202322515?

    Post summary

    The post announces a TryHackMe tutorial that demonstrates how to exploit CVE-2023-22515 to gain admin access in Confluence Server and Data Center editions.

    00011139
    436 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    Two Atlassian Confluence Server and Data Center zero-day flaws, CVE-2022-26134 and CVE-2023-22515, have been exploited in the wild by multiple actors, according to Rapid7 and Volexity. https://threatcluster.io/cluster/critical-zero-day-vulnerabilities-in-atlassian-confluence-ex-49e124f7

    Post summary

    Multiple actors are actively exploiting the two Atlassian Confluence zero‑day vulnerabilities CVE‑2022‑26134 and CVE‑2023‑22515, as reported by Rapid7 and Volexity.

    0000091
    356 followersView on X
  • Sun4lower@LittleSun4lower
    PoC

    I just completed Confluence CVE-2023-22515 room on TryHackMe! Exploit CVE-2023-22515 to get admin access to Confluence Server and Data Center editions. https://tryhackme.com/room/confluence202322515?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #Consistency #cyberverse #vulnerability

    Post summary

    User completed a TryHackMe room demonstrating the exploitation of Confluence CVE‑2023‑22515 for admin access.

    0000075
    5 followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    General

    I just completed Confluence CVE-2023-22515 room on TryHackMe! Exploit CVE-2023-22515 to get admin access to Confluence Server and Data Center editions. https://tryhackme.com/room/confluence202322515?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The post announces completion of a TryHackMe room on CVE-2023-22515 and notes the exploit allows admin access to Confluence, but it provides no PoC, exploit code, or patch information.

    0000046
  • Roman@mrBr4un
    Exploit

    I just completed Confluence CVE-2023-22515 room on TryHackMe! Exploit CVE-2023-22515 to get admin access to Confluence Server and Data Center editions. https://tryhackme.com/room/confluence202322515?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=68639866ce8287add0b55c97 #tryhackme через @tryhackme

    Post summary

    The post promotes a TryHackMe room that teaches how to exploit Confluence CVE‑2023‑22515 for admin access, but it does not provide actual exploit code or evidence of real‑world attacks.

    0000065
    57 followersView on X
  • Secwiser - Cyber Security Insights@Secwiserapp
    Active Exploitation

    Confluence 0-day: setup grants admin access Concise incident summary: CVE-2023-22515 in Atlassian Confluence enables unauthenticated users to force Setup Mode, create a persistent admin account, and complete setup, gaining full control. Exploited via curl to /setup/*; urgent containment and forensic review recommended. Read more: https://medium.com/@owaisalikhan081/soc235-atlassian-confluence-broken-access-control-0-day-cve-2023-22515-a420cf431747?source=rss------cybersecurity-5 Discover the app: https://www.secwiser.com/app #CyberSecurity #ApplicationSecurity #WebSecurity #VulnerabilityManagement #CVE2023-22515 #SecureDevOps #OWASP #ThreatDetection #CyberDefense #ZeroDay #Secwiser #InfoSec

    Post summary

    CVE-2023-22515 in Atlassian Confluence allows unauthenticated users to trigger Setup Mode, create a persistent admin account, and gain full control; the vulnerability has been actively exploited via a simple curl request.

    0000061
    14 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appatlassianconfluence_data_center---
Appatlassianconfluence_server---

Explore more