peter bassill · operator
$ cve CVE-2022-26133 JSON

CVE-2022-26133

9.8
CRITICAL · CVSS 3.1 · EPSS 70.4% (pctl 99)

Patch early

EPSS 70.4% — above the 10% action threshold.

Description

SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS70.39% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2022-04-20
Last modified2026-06-17

Affected (1)

VendorProduct
atlassianbitbucket data center

References

→ the Explorer  ·  watch your stack  ·  NVD