CVE-2023-22515
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
10 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.35%
probability
This CVE has a 94.35% probability
of being exploited in the next 30 days.
0%
Top 100.0th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroBroken access control vulnerability
Google Project Zero
Patched
Oct. 4, 2023
Reported by
???
Root Cause Analysis
???
Exploits & PoC
Chocapikk/CVE-2023-22515
CVE-2023-22515: Confluence Broken Access Control Exploit
151
ad-calcium/CVE-2023-22515
Confluence未授权添加管理员用户(CVE-2023-22515)漏洞利用工具
111
ErikWynter/CVE-2023-22515-Scan
Scanner for CVE-2023-22515 - Broken Access Control Vulnerability in Atlassian Confluence
78
AIex-3/confluence-hack
CVE-2023-22515
52
K4ptor/CVE-2023-22515
Confluence Unauthorized Administrator User Addition Exploitation Script
25
Le1a/CVE-2023-22515
Confluence Data Center & Server 权限提升漏洞 Exploit
6
kh4sh3i/CVE-2023-22515
CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server
4
7 repos — triés par ⭐
Rechercher sur GitHub ↗
Microsoft: State hackers exploiting Confluence zero-day since September
BleepingComputer
Oct 11, 2023
Atlassian patches critical Confluence zero-day exploited in attacks
BleepingComputer
Oct 04, 2023
Defense Lessons From the Black Basta Ransomware Playbook
Qualys
Feb 25, 2025
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable-Research
May 27, 2026
Microsoft Warns of Nation-State Hackers Exploiting Critical Atlassian Confluence Vulnerability
TheHackerNews
Atlassian Confluence Broken Access Control Vulnerability (CVE-2023-22515)
Qualys
Nov 15, 2023
Security Advisory 2023-073
CERT-EU
Oct 06, 2023
Signal Intelligence
Confidence
92%
EPSS
94.35%
Mentions
10
Last Seen
May 27, 2026
CNA Information
Analyst Note
CVE-2023-22515 is a critical zero-day vulnerability (CVSS 10.0) in Confluence Data Center/Server that enables unauthorized admin account creation, confirmed by Atlassian and reported by Google Project Zero. The vulnerability affects publicly accessible instances with real-world exploitation evidence, though CISA KEV listing and broader coverage remain limited.
Threat Actors 18
MuddyWater
apt_group
Information theft and espionage
🇮🇷 IR
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT37
apt_group
Information theft and espionage
🇰🇵 KP
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Kimsuky
apt_group
Information theft and espionage
🇰🇷 KR
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
Hacking Team
apt_group
🇮🇹 IT
Tick
apt_group
Information theft and espionage
🇨🇳 CN
UAC-0020
apt_group
🇺🇦 UA
SideWinder
apt_group
🇮🇳 IN
RAZOR TIGER
apt_group
Information theft and espionage
🇮🇳 IN
Larva-208
apt_group
🇷🇺 RU
Storm-0530
apt_group
🇰🇵 KP
Moonstone Sleet
apt_group
🇰🇷 KR
Storm-0062
apt_group
🇨🇳 CN
Ukrainian Cyber Alliance
apt_group
🇺🇦 UA
Operation Black Atlas
apt_group
Financial crime
Triage Info
Decided atMar 03, 2026