CVE-2022-26133: Critical severity atlassian bitbucket vulnerability
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26133?
The severity of CVE-2022-26133 is critical with a CVSS score of 9.8.
How does CVE-2022-26133 affect Atlassian Bitbucket Data Center?
CVE-2022-26133 affects Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0.
Can an unauthenticated attacker exploit CVE-2022-26133?
Yes, an unauthenticated attacker can exploit CVE-2022-26133.
How can an attacker exploit CVE-2022-26133?
An attacker can exploit CVE-2022-26133 by executing arbitrary code via Java deserialization.
Are there any references available for CVE-2022-26133?
Yes, you can find references for CVE-2022-26133 at the following links: [Reference 1](https://confluence.atlassian.com/security/multiple-products-security-advisory-hazelcast-vulnerable-to-remote-code-execution-cve-2016-10750-1116292387.html), [Reference 2](https://jira.atlassian.com/browse/BSERV-13173).