EXPOSURES › CVE-2023-22515
CVE-2023-22515
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAtlassian Confluence Data Center and Server suffered a broken access control flaw allowing attackers to create unauthorized admin accounts and access the system.
The vulnerability allowed attackers to bypass access controls, create unauthorized administrator accounts, and gain full access to Confluence Data Center and Server. For DIB organizations, this represents a severe compliance impact as it enables privilege escalation and unauthorized data access, violating CMMC/NIST 800-171 requirements for access control and system integrity. Organizations must ensure all Confluence instances are patched immediately and monitor for unauthorized account creation.
Shame score — A broken access control flaw in a widely deployed collaboration platform that was actively exploited in the wild and linked to ransomware attacks, demonstrating severe negligence and avoidability.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.