CVE-2023-22518
Confluence improper authorization - unauthenticated restore/takeover of the instance
- Severity
- critical
- Affected product
- Atlassian Confluence
- Affected versions
- Atlassian Confluence < 7.19.16
- Affected versions
- Atlassian Confluence ≥ 8.0.0, < 8.3.4
- Affected versions
- Atlassian Confluence ≥ 8.4.0, < 8.4.4
- Affected versions
- Atlassian Confluence ≥ 8.5.0, < 8.5.3
- Fixed in
- Atlassian Confluence 7.19.16 (7.19 LTS), 8.3.4, 8.4.4, 8.5.3, 8.6.0
- Fixed in
- Atlassian Confluence 8.3.4
- Fixed in
- Atlassian Confluence 8.4.4
- Fixed in
- Atlassian Confluence 8.5.3
- CISA KEV
- Listed as a known exploited vulnerability
- Added to NewScan
- 2026-08-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Atlassian Confluence appliance and reports this CVE when the detected version falls inside the affected range below.
Atlassian fixed this on FIVE branches, so the single `lt 8.5.4` this row used to carry was a false positive on every patched install between 7.19.16 and 8.5.3 - a 7.19.18 LTS, one of the most common versions in the field, read as verified-vulnerable to a KEV CVE it was patched against. Deliberately re-bounded DOWN to the lowest fixed version: `lt 7.19.16` is a strict subset of the affected set, so it can only ever under-fire. The 8.x branch rows this needs (ge 8.0.0/lt 8.3.4, ge 8.4.0/lt 8.4.4, ge 8.5.0/lt 8.5.3) are held until the appliance_tools `ge`-honouring fix is in a RELEASED image: published today they would be read by existing installs as `lt` alone, which is broader than the bug being fixed. Backlog D80.
APPLIANCE FINGERPRINT
NewScan fingerprints the Atlassian Confluence appliance and reports this CVE when the detected version falls inside the affected range below.
The 8.0.0-8.3.3 arm of the five-branch fix (8.3.4 / 8.4.4 / 8.5.3 / 8.6.0-clean / 7.19.16 LTS). One of the three 8.x rows D80 held until appliance_tools honoured ge/le in a RELEASED image - it shipped 2026-08-07 and sixteen daily releases have carried it since, so existing installs read the full range, not a bare lt. The re-bounded lt 7.19.16 row above stays as the pre-8 arm and the under-firing floor; 8.6.0+ needs no row (clean at release).
APPLIANCE FINGERPRINT
NewScan fingerprints the Atlassian Confluence appliance and reports this CVE when the detected version falls inside the affected range below.
The 8.4.x arm of CVE-2023-22518 (see the 8.0-8.3.3 row for the D80 history).
APPLIANCE FINGERPRINT
NewScan fingerprints the Atlassian Confluence appliance and reports this CVE when the detected version falls inside the affected range below.
The 8.5.0-8.5.2 arm of CVE-2023-22518. Note the sibling CVE-2023-22515 row above already bounds 8.0.0-8.5.2 with ge/le honoured on the same engine - the two KEV ids share the branch geometry, and 22515's row was the precedent that proved the released engine reads these correctly.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →