← All CVEs NewScan detects
criticalKEV

CVE-2023-22518

Confluence improper authorization - unauthenticated restore/takeover of the instance

Severity
critical
Affected product
Atlassian Confluence
Affected versions
Atlassian Confluence < 7.19.16
Affected versions
Atlassian Confluence ≥ 8.0.0, < 8.3.4
Affected versions
Atlassian Confluence ≥ 8.4.0, < 8.4.4
Affected versions
Atlassian Confluence ≥ 8.5.0, < 8.5.3
Fixed in
Atlassian Confluence 7.19.16 (7.19 LTS), 8.3.4, 8.4.4, 8.5.3, 8.6.0
Fixed in
Atlassian Confluence 8.3.4
Fixed in
Atlassian Confluence 8.4.4
Fixed in
Atlassian Confluence 8.5.3
CISA KEV
Listed as a known exploited vulnerability
Added to NewScan
2026-08-02
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Atlassian Confluence appliance and reports this CVE when the detected version falls inside the affected range below.

Atlassian fixed this on FIVE branches, so the single `lt 8.5.4` this row used to carry was a false positive on every patched install between 7.19.16 and 8.5.3 - a 7.19.18 LTS, one of the most common versions in the field, read as verified-vulnerable to a KEV CVE it was patched against. Deliberately re-bounded DOWN to the lowest fixed version: `lt 7.19.16` is a strict subset of the affected set, so it can only ever under-fire. The 8.x branch rows this needs (ge 8.0.0/lt 8.3.4, ge 8.4.0/lt 8.4.4, ge 8.5.0/lt 8.5.3) are held until the appliance_tools `ge`-honouring fix is in a RELEASED image: published today they would be read by existing installs as `lt` alone, which is broader than the bug being fixed. Backlog D80.

APPLIANCE FINGERPRINT

NewScan fingerprints the Atlassian Confluence appliance and reports this CVE when the detected version falls inside the affected range below.

The 8.0.0-8.3.3 arm of the five-branch fix (8.3.4 / 8.4.4 / 8.5.3 / 8.6.0-clean / 7.19.16 LTS). One of the three 8.x rows D80 held until appliance_tools honoured ge/le in a RELEASED image - it shipped 2026-08-07 and sixteen daily releases have carried it since, so existing installs read the full range, not a bare lt. The re-bounded lt 7.19.16 row above stays as the pre-8 arm and the under-firing floor; 8.6.0+ needs no row (clean at release).

APPLIANCE FINGERPRINT

NewScan fingerprints the Atlassian Confluence appliance and reports this CVE when the detected version falls inside the affected range below.

The 8.4.x arm of CVE-2023-22518 (see the 8.0-8.3.3 row for the D80 history).

APPLIANCE FINGERPRINT

NewScan fingerprints the Atlassian Confluence appliance and reports this CVE when the detected version falls inside the affected range below.

The 8.5.0-8.5.2 arm of CVE-2023-22518. Note the sibling CVE-2023-22515 row above already bounds 8.0.0-8.5.2 with ge/le honoured on the same engine - the two KEV ids share the branch geometry, and 22515's row was the precedent that proved the released engine reads these correctly.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →