CVE-2023-22515: Atlassian Confluence Privilege Escalation
Can Confluence be compromised by unauthenticated attackers?
A broken access control vulnerability in Atlassian Confluence that allows unauthenticated attackers to create administrator accounts through the server setup process. Accessible via crafted HTTP requests to exposed Confluence instances.
Impact & Exploitation
CVSS 10.0. Exploited by Chinese APT Storm-0062. Enables complete Confluence takeover, access to all documentation, and potential supply chain compromise through CI/CD integration.
How Precogs AI Detects Atlassian Confluence Privilege Escalation
Precogs AI detects access control bypass in compiled web applications, identifying exposed admin setup endpoints and broken authorization in collaboration platform binaries.