EIP-2026-104175

PRE-CVE

Atlassian Confluence Data Center and Server - Authentication Bypass (Metasploit)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104175. PoCs published by Emir Polat.

AI-analyzed exploit summary This Metasploit module exploits CVE-2023-22515, a broken access control vulnerability in Atlassian Confluence, allowing unauthenticated creation of an admin account. It bypasses authentication by manipulating the setup process and creating a new user with administrative privileges.

Description

Atlassian Confluence Data Center and Server - Authentication Bypass (Metasploit)

Exploits (1)

exploitdb WORKING POC
by Emir Polat · rubywebappsmultiple
https://www.exploit-db.com/exploits/51829

This Metasploit module exploits CVE-2023-22515, a broken access control vulnerability in Atlassian Confluence, allowing unauthenticated creation of an admin account. It bypasses authentication by manipulating the setup process and creating a new user with administrative privileges.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Atlassian Confluence Data Center and Server (versions 8.0.0-8.3.2, 8.4.0-8.4.2, 8.5.0-8.5.1)
No auth needed
Prerequisites: Network access to the Confluence server · Confluence server with vulnerable version
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026