criticalKEV
CVE-2022-26134
Confluence OGNL injection - unauthenticated remote code execution
- Severity
- critical
- Affected product
- Atlassian Confluence
- Affected versions
- Atlassian Confluence < 7.4.17
- Fixed in
- Atlassian Confluence 7.4.17
- CISA KEV
- Listed as a known exploited vulnerability
- Added to NewScan
- 2026-08-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Atlassian Confluence appliance and reports this CVE when the detected version falls inside the affected range below.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →