S4E just found a high-severity finding from cve-2026-42945 scanner (version based)
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-36804 Scanner

CVE-2022-36804 scanner - Remote Code Execution (RCE) vulnerability in Atlassian Bitbucket Server and Bitbucket Data Center

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-36804
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Bitbucket Serverby Atlassian
AFFECTED< unspecifiedSAFE ✓≥ unspecified
Bitbucket Data Centerby Atlassian
AFFECTED< unspecifiedSAFE ✓≥ unspecified
Updated Aug 22, 2026View on NVD →
Detail

Atlassian Bitbucket Server and Bitbucket Data Center are products developed by Atlassian that provide users with a collaborative platform for software development. The products are designed to facilitate the creation, sharing and management of code repositories. The platform is particularly useful for teams that are working remotely, or for those who want to monitor and control the development process of various software. With Bitbucket Server and Data Center, developers can easily collaborate with team members, track and manage changes to their code, and debug their programs.

Recently, a vulnerability was detected in the platform, with a CVE code of CVE-2022-36804. This vulnerability allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability affects the Bitbucket Server and Data Center versions 7.0.0 through 7.6.17, 7.7.0 through 7.17.10, 7.18.0 through 7.21.4, 8.0.0 through 8.0.3, 8.1.0 through 8.1.3, 8.2.0 through 8.2.2, and 8.3.0 through 8.3.1.

If exploited, this vulnerability can lead to severe consequences such as unauthorized access to systems, data theft, and data loss. If an attacker can execute arbitrary code, it provides them with elevated privileges and complete control over the targeted system, making it possible for them to extract sensitive information or engage in other malicious activities.

In conclusion, Atlassian Bitbucket Server and Data Center are useful tools for software development, but the CVE-2022-36804 vulnerability highlights the need for proper security measures and protocols. Those who rely on this platform should take precautions to protect their systems and sensitive data. s4e.io offers pro features to help users ensure that their digital assets are safe from vulnerabilities. By subscribing to the platform, users can learn about the latest threats and protect their systems from malicious attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take several precautions, including:

  • Updating their Bitbucket Server and Data Center software to the latest version.
  • Configuring a firewall to limit access to the Bitbucket website.
  • Limiting the number of permissions granted to untrusted users.
  • Enforcing two-factor authentication for all users.
  • Regularly monitoring the platform for suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.