ZeroHour

CVE-2022-26138

KEVmoderate

Hard-coded Credentials in Atlassian Questions for Confluence App

CISA: Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

CVSS 3.1
9.8 critical
EPSS
98%p100
Published
()
KEV added
AI analysis

The Questions for Confluence app for Confluence Server and Data Center, when versions 2.7.34, 2.7.35, or 3.0.2 are installed, creates a user account named disabledsystemuser in the confluence-users group protected by a hard-coded password (CWE-798). Because the credential is embedded in the app, any remote, unauthenticated attacker who knows the password can log in to Confluence without a valid account. Successful exploitation grants access to all content that is accessible to the confluence-users group, which typically spans most of the instance's spaces and pages. Only Confluence Server and Data Center deployments that installed one of those app versions are affected, and the created account persists after installation. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-07-29 and carries a 98.2% EPSS score (100th percentile).

What to do: Upgrade the Questions for Confluence app to a fixed release per Atlassian's instructions, as required by the CISA KEV catalog. Check whether an account named disabledsystemuser exists in the confluence-users group; if present, delete it or change its hard-coded password, and review authentication logs for logins using that account. Prioritize internet-exposed Confluence Server and Data Center instances.

Affected
Atlassian Questions for Confluence app for Confluence Server and Data Center2.7.34, 2.7.35, and 3.0.2 (the disabledsystemuser account is created when these versions are installed and persists afterward)
Estimated exposure
moderatelikely thousands of Confluence Server/Data Center instances (only those that installed the three named app versions) — No install counts are provided in the data, so this is an order-of-magnitude estimate from deployment patterns: Marketplace-style apps for self-hosted Confluence Server/DC typically run thousands to tens of thousands of installs, only the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

CISA Known Exploited Vulnerability
Affected
Atlassian Confluence
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
atlassian
Products
questions for confluence
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news