CVE-2022-26133

CRITICAL

Atlassian Bitbucket Data Center <7.17.6 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 5 public exploits for CVE-2022-26133. PoCs published by Pear1y, abbarhissarh, ar2o3.

AI-analyzed exploit summary This is a Python-based exploit for CVE-2022-26133, a deserialization vulnerability in Atlassian Bitbucket Data Center. The PoC generates a malicious payload to achieve remote code execution (RCE) via a reverse shell.

Description

SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.

Exploits (5)

nomisec WORKING POC 148 stars
by Pear1y · poc
https://github.com/Pear1y/CVE-2022-26133

This is a Python-based exploit for CVE-2022-26133, a deserialization vulnerability in Atlassian Bitbucket Data Center. The PoC generates a malicious payload to achieve remote code execution (RCE) via a reverse shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Atlassian Bitbucket Data Center
No auth needed
Prerequisites: Network access to the target · Target must be vulnerable to CVE-2022-26133
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 3 stars
by abbarhissarh · poc
https://github.com/abbarhissarh/CVE-2022-26133

This repository contains a functional exploit for CVE-2022-26133, a Java deserialization vulnerability in Atlassian Bitbucket Data Center. The exploit generates a malicious payload to achieve remote code execution (RCE) via crafted network requests.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Atlassian Bitbucket Data Center (versions 5.14.0 to 7.6.14, 7.7.0 to 7.17.6, 7.18.0 to 7.18.4, 7.19.0 to 7.19.4, 7.20.0)
No auth needed
Prerequisites: Network access to the target Bitbucket instance · Python 2.x environment with required dependencies
devstral-2 · analyzed Apr 10, 2026 Full analysis →
nomisec WORKING POC 3 stars
by ar2o3 · poc
https://github.com/ar2o3/CVE-2022-26133

This repository contains a Python-based exploit for CVE-2022-26133, a deserialization vulnerability in Atlassian Bitbucket Data Center. The exploit generates a malicious payload to achieve remote code execution (RCE) via Java deserialization.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Atlassian Bitbucket Data Center (versions 5.14.0 to 7.6.13, 7.7.0 to 7.17.5, 7.18.0 to 7.18.3, 7.19.0 to 7.19.3, 7.20.0)
No auth needed
Prerequisites: Network access to the target Bitbucket instance · Python 2.x environment with required dependencies
devstral-2 · analyzed Feb 16, 2026 Full analysis →
inthewild WORKING POC
poc
https://github.com/0xstarford/cve-2022-26133

This repository contains a functional exploit for CVE-2022-26133, a Java deserialization vulnerability in Atlassian Bitbucket Data Center. The exploit generates a malicious payload to achieve remote code execution (RCE) via deserialization.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Atlassian Bitbucket Data Center (versions 5.14.0 to 7.6.14, 7.7.0 to 7.17.6, 7.18.0 to 7.18.4, 7.19.0 to 7.19.4, 7.20.0)
No auth needed
Prerequisites: Network access to the target Bitbucket instance · Python 2.x environment with required dependencies
devstral-2 · analyzed Feb 23, 2026 Full analysis →
inthewild WORKING POC
poc
https://github.com/0xabbarhsf/cve-2022-26133

This repository contains a functional exploit for CVE-2022-26133, a Java deserialization vulnerability in Atlassian Bitbucket Data Center. The exploit generates a malicious payload to achieve remote code execution (RCE) via deserialization.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Atlassian Bitbucket Data Center (versions 5.14.0 to 7.6.14, 7.7.0 to 7.17.6, 7.18.0 to 7.18.4, 7.19.0 to 7.19.4, 7.20.0)
No auth needed
Prerequisites: Network access to the target Bitbucket instance · Python 2.x environment with required dependencies
devstral-2 · analyzed Feb 23, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.7139
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-502
Status published
Products (2)
atlassian/bitbucket_data_center 7.20.0
atlassian/bitbucket_data_center 5.14.0 - 7.6.14
Published Apr 20, 2022
Tracked Since Feb 18, 2026