Vulnerability threat dossier

CVE-2022-26134

atlassianconfluence data center

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

VTP deterministic threat62.0of 100 · CVSS excluded

VTP analyst assessment

Confluence OGNL injection RCE

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV

Assessment

Critical unauthenticated OGNL injection in affected Confluence Server and Data Center releases enables arbitrary code execution. Public known exploitation and known ransomware-campaign use are recorded; VTP observation remains unknown.

Why it matters

  • Internet-accessible Confluence instances can be compromised without credentials or user interaction.
  • The 0.99999 EPSS score is predictive context, not additional exploitation proof.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The supplied press excerpt mentions botnet exploitation of known flaws but does not clearly attribute activity to this CVE.

Current campaign scope and first-party activity are not established.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Requests containing OGNL-like expressions or command syntax.

AI baseline history (3)
  1. BASELINE ASSESSED
    Confluence OGNL injection RCEgpt-5.6-sol · high
  2. BASELINE ASSESSED
    Exploited unauthenticated Confluence RCEgpt-5.6-sol · high
  3. BASELINE ASSESSED
    Atlassian Confluence unauthenticated OGNL injectiongpt-5.6-sol · high
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 1.00; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

1 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2022-26134ACTIVE
Evidence
04

Event history

Threat timeline

  1. 00:0002 Jun
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

  2. 00:0002 Jun
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including

CVE-2007-3010CVE-2016-6277CVE-2018-14558CVE-2019-14931CVE-2020-10987CVE-2021-36260CVE-2021-46422CVE-2022-26134CVE-2022-29464CVE-2022-30525CVE-2022-37055CVE-2023-1389CVE-2024-10914CVE-2024-29269CVE-2024-4577CVE-2025-10123CVE-2025-1974CVE-2025-55583
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2022-26134

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2022-26134
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score62.0vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction20 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-917
CPE records
4
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.