CVE-2022-26138: Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.
Other sources
Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Operational
Identify Confluence instances where the Atlassian Questions For Confluence app versions 2.7.34, 2.7.35, or 3.0.2 are installed. In Confluence Administration -> User Management, locate the user account with username "disabledsystemuser" (the hard-coded account the app creates) and delete that account. If deletion is not immediately possible, disable the account and change its password to a strong, unique password. Verify no other accounts with hard-coded credentials were created by the app.
Event History
Frequently Asked Questions
What is CVE-2022-26138?
CVE-2022-26138 is a vulnerability in the Atlassian Questions For Confluence app that allows remote, unauthenticated attackers to exploit hard-coded credentials.
What is the severity of CVE-2022-26138?
CVE-2022-26138 has a severity rating of 9.8 (critical).
Which software versions are affected by CVE-2022-26138?
CVE-2022-26138 affects Atlassian Questions For Confluence versions 2.7.34, 2.7.35, and 3.0.2.
How can remote, unauthenticated attackers exploit CVE-2022-26138?
Remote, unauthenticated attackers with knowledge of the hardcoded password can exploit CVE-2022-26138.
Are Atlassian Confluence Data Center and Atlassian Confluence Server affected by CVE-2022-26138?
No, Atlassian Confluence Data Center and Atlassian Confluence Server are not affected by CVE-2022-26138.