CVE-2023-22518CISA KEVEPSS p100.0%

CVE-2023-22518Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

Atlassian / Confluence Data Center and Server

Description

Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.

Scoring

EPSS100.00% probability of exploitation · percentile 100.0% · 2026-06-15T12:03:41Z

CISA KEV entry

Added to KEV: 2023-11-07

(incoming)1

TypeTargetConfidenceTier
KEVEntryAtlassian Confluence Data Center and Server Improper Authorization Vulnerabilitykev-cve-2023-225180%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
CVE
Atlassian Confluence Data Center and Server Template Injection Vulnerability
CVE
Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability
CVE
Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability
CVE
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
CVE
Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.