S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-26138 Scanner

CVE-2022-26138 scanner - Hard-Coded Credentials vulnerability in Atlassian Questions For Confluence

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-26138
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Questions For Confluenceby Atlassian
2.7.34
Updated Aug 22, 2026View on NVD →
Detail

Atlassian Questions For Confluence is a popular app used by organizations to create and manage questions and answers for their Confluence Server and Data Center. This app provides an efficient and collaborative way for teams to discuss ideas and gather feedback. With the Atlassian Questions For Confluence, users can easily create and manage polls, surveys, and quizzes, and track responses in real-time. The app also allows for integration with other Atlassian tools, such as Jira and Trello, making it a comprehensive solution for team collaboration.

Recently, a major vulnerability was detected in Atlassian Questions For Confluence, identified by the CVE-2022-26138 code. This vulnerability creates a serious risk to users’ data, as it creates a hard-coded account with a pre-set password. A remote, unauthenticated attacker who gains knowledge of this password could easily exploit the vulnerability to access user data and other sensitive information. Once exploited, this vulnerability could lead to a complete system compromise, put users’ personal information at risk, and even prompt severe legal repercussions.

When exploited, this vulnerability could lead to the exposure of a wide range of private and sensitive information, including confidential corporate information, user credentials, and intellectual property. The exploit would grant an attacker full administrative privileges, allowing them to access and modify user accounts, including deleting such accounts. The consequences of data breaches are severe, with organizations exposed to potential lawsuits, reputational damages, and financial losses.

s4e.io is a platform that takes cybersecurity seriously, and its pro features are critical in protecting an organization's digital assets. Users of the platform can easily and quickly learn about vulnerabilities and get comprehensive solutions on how to deal with them, ensuring their networks remain safe and secure. With the proactive approach offered by s4e.io, users of Atlassian Questions For Confluence can now protect themselves against the CVE-2022-26138 vulnerability, and relax knowing their confidential and proprietary information is safe from attackers.

 

REFERENCES

Solution Advice

To protect against this vulnerability, here are some precautions that organizations should take:

  • Update the Atlassian Questions For Confluence app to the most recent version that is not affected by this vulnerability.
  • Have a strong password policy for all user accounts.
  • Ensure that the Confluence instance is behind a firewall and only available to authorized users.
  • Perform regular vulnerability assessments and penetration testing.
  • Remove any unnecessary user accounts, groups, and permissions.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.