FAIL › dossier
Confluence Data Center and Server
PRODUCT· dossier confidence 20%
Atlassian Confluence Data Center and Server is a collaborative knowledge workspace product that has demonstrated a pattern of critical security vulnerabilities, including unauthenticated remote code execution and broken access controls. These flaws have been actively exploited in the wild, indicating a significant risk to organizations relying on this product for sensitive data management.
PROFILE
Categorycollaborative knowledge workspaceWhat they doAtlassian Confluence Data Center and Server is a collaborative knowledge workspace product for document collaboration and team knowledge management.
Websitehttps://www.atlassian.com/confluence ↗
SECURITY POSTURE
The product has a history of critical remote code execution vulnerabilities, including CVE-2021-26084 and CVE-2019-3398, both of which were actively exploited in the wild.
Notable failures
- CVE-2023-22527: Unauthenticated OGNL template injection RCE
- CVE-2023-22518: Unauthenticated improper authorization flaw causing data loss
- CVE-2023-22515: Broken access control allowing unauthorized admin account creation
Patterns: repeated critical unauthenticated RCE and access control flaws; vulnerabilities actively exploited in the wild
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-01-24 | CVE-2023-22527 | critical | Unauthenticated OGNL template injection in Atlassian Confluence Data Center and Server allows remote code execution. |
| 2023-11-07 | CVE-2023-22518 | critical | An unauthenticated attacker could exploit an improper authorization flaw in Atlassian Confluence Data Center and Server to cause significant data loss. |
| 2023-10-05 | CVE-2023-22515 | critical | Atlassian Confluence Data Center and Server suffered a broken access control flaw allowing attackers to create unauthorized admin accounts and access the system. |
DOSSIER SOURCES
- FAQ for CVE-2023-22527 - Atlassian Support · support.atlassian.com
- Security Advisories | Atlassian · www.atlassian.com
- CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In ... · confluence.atlassian.com
Open questions: Current patch status for CVE-2023-22527 · Atlassian's current vulnerability disclosure timeline
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-27 04:05:17.756760+00:00