← back
CVE-2022-26133criticalCWE-502

CVE-2022-26133

75Vexday Risk Score

Keep watching. It has a public proof of concept.

ssvc Attendcvss 9.8epss 71%
from disclosure to weapon19 days
Published on NVDApr 20
1st PoC+19d
exploitation probability
71%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.