// CVE

CVE-2023-22518

Critical 10.0

Atlassian Confluence Data Center

10.0CVSS
100%EPSS
CISA KEV

Summary

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrat…

Published: 2023-10-31

Analysis

🟠 High — imminent exploitation

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

The vector encodes how it's exploited (translated above, in the analysis). Break it down in the CVSS tool →

← Back to the Threat Radar

Sources: CISA KEV · EPSS · FIRST.org · NVD. Analysis derived from the CVSS vector and exploitation status (no AI). Informational; always verify against the vendor's official advisory.