SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Critical RCE Flaw Discovered In Confluence: CVE-2023-22522

Critical RCE Flaw Discovered In Confluence: CVE-2023-22522

A new remote code execution vulnerability has been found in Confluence Data Center and Server. CVE-2023-22522, exploited using template injection, allows authenticated attackers (including those with anonymous access) to inject malicious user input into Confluence pages. What’s more, this vulnerabil...

Dec 6, 2023By Meghana Raatni2 min read

A new remote code execution vulnerability has been found in Confluence Data Center and Server. CVE-2023-22522, exploited using template injection, allows authenticated attackers (including those with anonymous access) to inject malicious user input into Confluence pages. What’s more, this vulnerability affects all versions of Confluence, starting from 4.0.0!

Atlassian rated this vulnerability a hefty 9.0 on the CVSS scale, branding it a critical flaw, and urged users to patch their software immediately.

Impact

Successful exploitation of this vulnerability can result in remote code being executed on your devices.

Affected Versions

Solution

A few mitigations are provided. You should back up your instance by following the steps provided in the linked documentation. Removing your instance from the internet until you can update it is also recommended.

Luckily for us, this vulnerability already has patches. We’ve displayed the fixed versions below.

The good news is that Atlassian Cloud sites are unaffected by this vulnerability! You don’t need to worry about this flaw if you use an atlassian.net domain to access Confluence. However, it’s still a good idea to keep your version of Confluence up to date. A patch management tool can help you with that.

You can install these patches using SanerNow. SanerNow Vulnerability Management, Risk Prioritization, and Patch Management detect and automatically fix vulnerabilities with risk-based remediation. With SanerNow, you can keep your systems updated and secure.

Featured Posts

Open One Request, Total Persistence: Inside the SharePoint Flaw Attackers Are Exploiting
One Request, Total Persistence: Inside the SharePoint Flaw Attackers Are Exploiting

CVE Research

One Request, Total Persistence: Inside the SharePoint Flaw Attackers Are Exploiting

A critical SharePoint deserialization flaw, CVE-2026-50522 (CVSS 9.8), is under active exploitation just weeks after its July 2026 patch, following a public PoC. Attackers are using it to steal IIS machine keys in a single request, gaining persistence that survives patching alone. Now on CISA's KEV list, it's the third actively exploited SharePoint flaw in recent months, patch immediately and rotate machine keys.

Jul 24, 2026

Open ENCFORGE Ransomware: Anatomy of an AI-Focused Cyber Attack
ENCFORGE Ransomware: Anatomy of an AI-Focused Cyber Attack

CVE Research

ENCFORGE Ransomware: Anatomy of an AI-Focused Cyber Attack

Jul 22, 2026

Open UTA0533 Weaponizes KNUCKLEBALL: Inside the SonicWall SMA Zero-Day Exploitation Chain
UTA0533 Weaponizes KNUCKLEBALL: Inside the SonicWall SMA Zero-Day Exploitation Chain

CVE Research

UTA0533 Weaponizes KNUCKLEBALL: Inside the SonicWall SMA Zero-Day Exploitation Chain

Jul 20, 2026

Open One Email, Full Session Takeover: Inside Zimbra's Critical Classic Web Client Code Execution Flaw
One Email, Full Session Takeover: Inside Zimbra's Critical Classic Web Client Code Execution Flaw

CVE Research

One Email, Full Session Takeover: Inside Zimbra's Critical Classic Web Client Code Execution Flaw

Jul 20, 2026

Critical RCE Flaw Discovered In Confluence: CVE-2023-22522 | SecPod