Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances.
Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 30 Jul 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Sep 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Status: PUBLISHED
Assigner: atlassian
Published: 2023-10-04T14:00:00.820Z
Updated: 2025-10-21T23:05:35.521Z
Reserved: 2023-01-01T00:01:22.331Z
Link: CVE-2023-22515
Updated: 2024-08-02T10:13:48.693Z
Status : Analyzed
Published: 2023-10-04T14:15:10.440
Modified: 2025-10-24T13:39:01.950
Link: CVE-2023-22515
No data.