CVE-2023-22515

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 10 articles

EPSS Score

Source: FIRST.org · 2026-05-24
94.35%
probability
This CVE has a 94.35% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Broken access control vulnerability

Attack Intelligence

Google Project Zero

Patched
Oct. 4, 2023
Reported by
???
Root Cause Analysis
???

Exploits & PoC

Chocapikk/CVE-2023-22515

CVE-2023-22515: Confluence Broken Access Control Exploit

151
ad-calcium/CVE-2023-22515

Confluence未授权添加管理员用户(CVE-2023-22515)漏洞利用工具

111
ErikWynter/CVE-2023-22515-Scan

Scanner for CVE-2023-22515 - Broken Access Control Vulnerability in Atlassian Confluence

78
52
K4ptor/CVE-2023-22515

Confluence Unauthorized Administrator User Addition Exploitation Script

25
Le1a/CVE-2023-22515

Confluence Data Center & Server 权限提升漏洞 Exploit

6
kh4sh3i/CVE-2023-22515

CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server

4
7 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 94.35%
Mentions 10
Last Seen May 27, 2026

CNA Information

Analyst Note

CVE-2023-22515 is a critical zero-day vulnerability (CVSS 10.0) in Confluence Data Center/Server that enables unauthorized admin account creation, confirmed by Atlassian and reported by Google Project Zero. The vulnerability affects publicly accessible instances with real-world exploitation evidence, though CISA KEV listing and broader coverage remain limited.

Threat Actors 18

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Cobalt
apt_group Financial crime 🇷🇺 RU
APT37
apt_group Information theft and espionage 🇰🇵 KP
APT 28
apt_group Information theft and espionage 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
Hacking Team
apt_group 🇮🇹 IT
Tick
apt_group Information theft and espionage 🇨🇳 CN
UAC-0020
apt_group 🇺🇦 UA
SideWinder
apt_group 🇮🇳 IN
RAZOR TIGER
apt_group Information theft and espionage 🇮🇳 IN
Larva-208
apt_group 🇷🇺 RU
Storm-0530
apt_group 🇰🇵 KP
Moonstone Sleet
apt_group 🇰🇷 KR
Storm-0062
apt_group 🇨🇳 CN
Ukrainian Cyber Alliance
apt_group 🇺🇦 UA
Operation Black Atlas
apt_group Financial crime

Triage Info

Decided atMar 03, 2026