← All CVEs NewScan detects
criticalKEV

CVE-2023-22518

Confluence improper authorization - unauthenticated restore/takeover of the instance

Severity
critical
Affected product
Atlassian Confluence
Affected versions
Atlassian Confluence < 7.19.16
Fixed in
Atlassian Confluence 7.19.16 (7.19 LTS), 8.3.4, 8.4.4, 8.5.3, 8.6.0
CISA KEV
Listed as a known exploited vulnerability
Added to NewScan
2026-08-02
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Atlassian Confluence appliance and reports this CVE when the detected version falls inside the affected range below.

Atlassian fixed this on FIVE branches, so the single `lt 8.5.4` this row used to carry was a false positive on every patched install between 7.19.16 and 8.5.3 - a 7.19.18 LTS, one of the most common versions in the field, read as verified-vulnerable to a KEV CVE it was patched against. Deliberately re-bounded DOWN to the lowest fixed version: `lt 7.19.16` is a strict subset of the affected set, so it can only ever under-fire. The 8.x branch rows this needs (ge 8.0.0/lt 8.3.4, ge 8.4.0/lt 8.4.4, ge 8.5.0/lt 8.5.3) are held until the appliance_tools `ge`-honouring fix is in a RELEASED image: published today they would be read by existing installs as `lt` alone, which is broader than the bug being fixed. Backlog D80.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →