CVE-2023-22518
Confluence improper authorization - unauthenticated restore/takeover of the instance
- Severity
- critical
- Affected product
- Atlassian Confluence
- Affected versions
- Atlassian Confluence < 7.19.16
- Fixed in
- Atlassian Confluence 7.19.16 (7.19 LTS), 8.3.4, 8.4.4, 8.5.3, 8.6.0
- CISA KEV
- Listed as a known exploited vulnerability
- Added to NewScan
- 2026-08-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Atlassian Confluence appliance and reports this CVE when the detected version falls inside the affected range below.
Atlassian fixed this on FIVE branches, so the single `lt 8.5.4` this row used to carry was a false positive on every patched install between 7.19.16 and 8.5.3 - a 7.19.18 LTS, one of the most common versions in the field, read as verified-vulnerable to a KEV CVE it was patched against. Deliberately re-bounded DOWN to the lowest fixed version: `lt 7.19.16` is a strict subset of the affected set, so it can only ever under-fire. The 8.x branch rows this needs (ge 8.0.0/lt 8.3.4, ge 8.4.0/lt 8.4.4, ge 8.5.0/lt 8.5.3) are held until the appliance_tools `ge`-honouring fix is in a RELEASED image: published today they would be read by existing installs as `lt` alone, which is broader than the bug being fixed. Backlog D80.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →