CVE-2023-22515: Atlassian Confluence Privilege Escalation

CRITICAL
10CRITICAL
Published: 2023-10-04Affected: Confluence Data Center/Server 8.0.0-8.5.1CWE-269

Can Confluence be compromised by unauthenticated attackers?

A broken access control vulnerability in Atlassian Confluence that allows unauthenticated attackers to create administrator accounts through the server setup process. Accessible via crafted HTTP requests to exposed Confluence instances.

Impact & Exploitation

CVSS 10.0. Exploited by Chinese APT Storm-0062. Enables complete Confluence takeover, access to all documentation, and potential supply chain compromise through CI/CD integration.

How Precogs AI Detects Atlassian Confluence Privilege Escalation

Precogs AI detects access control bypass in compiled web applications, identifying exposed admin setup endpoints and broken authorization in collaboration platform binaries.

Precogs Logo

Precogs Research

This vulnerability intelligence report was analyzed and enriched by the Precogs AI Security Team. Our researchers continuously monitor emerging threats across AI code, LLM pipelines, and binary architectures to ensure accurate real-time remediation guidance.