logo

Security alert: privilege escalation vulnerability in Confluence Data Center and Server, CVE-2023-22515

ID: 3fcac2ff-a876-5dd4-a179-e30a983ef3e3

STIX ID: report--3fcac2ff-a876-5dd4-a179-e30a983ef3e3

Feed Name: Expel Blog

Threat Score
85/100

Date Published: 2023-10-04

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

A critical privilege-escalation vulnerability (CVE-2023-22515) in Atlassian Confluence Data Center and Server versions 8.0–8.5.1 is being actively exploited to allow attackers to create administrative accounts on external-facing servers; Atlassian has released a patch and organizations are advised to upgrade/apply the patch and search for IOCs such as unexpected confluence-administrator group members or newly created user accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.