A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim’s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4.
Conclusion & alert: CVE-2022-26137 is rated Moderate Risk (63.2/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.78%). Core evidence: EPSS rose +1.66% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.12% | 1.78% | +1.66% |
| 2 | 2026-04-01 | 0.22% | 0.12% | -0.10% |
| 3 | 2026-03-04 | — | 0.22% | — |
Full EPSS history (30 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| atlassian | bamboo | >= 7.2.0, < 7.2.10 | cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:* |
| atlassian | bamboo | >= 8.0.0, < 8.0.9 | cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:* |
| atlassian | bamboo | >= 8.1.0, < 8.1.8 | cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:* |
| atlassian | bamboo | >= 8.2.0, < 8.2.4 | cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:* |
| atlassian | bitbucket | < 7.6.16 | cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* |
| atlassian | bitbucket | >= 7.7.0, < 7.17.8 | cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* |
| atlassian | bitbucket | >= 7.18.0, < 7.19.5 | cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* |
| atlassian | bitbucket | >= 7.20.0, < 7.20.2 | cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* |
| atlassian | bitbucket | >= 7.21.0, < 7.21.2 | cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* |
| atlassian | bitbucket | 8.0.0 | cpe:2.3:a:atlassian:bitbucket:8.0.0:*:*:*:*:*:*:* |
| atlassian | bitbucket | 8.1.0 | cpe:2.3:a:atlassian:bitbucket:8.1.0:*:*:*:*:*:*:* |
| atlassian | confluence_data_center | < 7.4.17 | cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:* |
| atlassian | confluence_data_center | >= 7.5.0, < 7.13.7 | cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:* |
| atlassian | confluence_data_center | >= 7.14.0, < 7.14.3 | cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:* |
| atlassian | confluence_data_center | >= 7.15.0, < 7.15.2 | cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:* |
| atlassian | confluence_data_center | >= 7.16.0, < 7.16.4 | cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:* |
| atlassian | confluence_data_center | >= 7.17.0, < 7.17.4 | cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:* |
| atlassian | confluence_data_center | 7.18.0 | cpe:2.3:a:atlassian:confluence_data_center:7.18.0:*:*:*:*:*:*:* |
| atlassian | confluence_server | < 7.4.17 | cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:* |
| atlassian | confluence_server | >= 7.5.0, < 7.13.7 | cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:* |
| atlassian | confluence_server | >= 7.14.0, < 7.14.3 | cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:* |
| atlassian | confluence_server | >= 7.15.0, < 7.15.2 | cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:* |
| atlassian | confluence_server | >= 7.16.0, < 7.16.4 | cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:* |
| atlassian | confluence_server | >= 7.17.0, < 7.17.4 | cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:* |
| atlassian | confluence_server | 7.18.0 | cpe:2.3:a:atlassian:confluence_server:7.18.0:*:*:*:*:*:*:* |
| atlassian | crowd | < 4.3.8 | cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:* |
| atlassian | crowd | >= 4.4.0, < 4.4.2 | cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:* |
| atlassian | crowd | 5.0.0 | cpe:2.3:a:atlassian:crowd:5.0.0:*:*:*:*:*:*:* |
| atlassian | crucible | < 4.8.10 | cpe:2.3:a:atlassian:crucible:*:*:*:*:*:*:*:* |
| atlassian | fisheye | < 4.8.10 | cpe:2.3:a:atlassian:fisheye:*:*:*:*:*:*:*:* |
| atlassian | jira_data_center | >= 8.13.0, < 8.13.22 | cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:* |
| atlassian | jira_data_center | >= 8.14.0, < 8.20.10 | cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:* |
| atlassian | jira_data_center | >= 8.21.0, < 8.22.4 | cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:* |
| atlassian | jira_server | >= 8.13.0, < 8.13.22 | cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:* |
| atlassian | jira_server | >= 8.14.0, < 8.20.10 | cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:* |
| atlassian | jira_server | >= 8.21.0, < 8.22.4 | cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:* |
| atlassian | jira_service_desk | < 4.13.22 | cpe:2.3:a:atlassian:jira_service_desk:*:*:*:*:data_center:*:*:* |
| atlassian | jira_service_desk | < 4.13.22 | cpe:2.3:a:atlassian:jira_service_desk:*:*:*:*:server:*:*:* |
| atlassian | jira_service_management | >= 4.14.0, < 4.20.10 | cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:* |
| atlassian | jira_service_management | >= 4.14.0, < 4.20.10 | cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:* |
| atlassian | jira_service_management | >= 4.21.0, < 4.22.4 | cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:* |
| atlassian | jira_service_management | >= 4.21.0, < 4.22.4 | cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:* |
| URL | Tags |
|---|---|
| https://jira.atlassian.com/browse/BAM-21795 | Issue Tracking Patch Vendor Advisory |
| https://jira.atlassian.com/browse/BSERV-13370 | Issue Tracking Patch Vendor Advisory |
| https://jira.atlassian.com/browse/CONFSERVER-79476 | Issue Tracking Patch Vendor Advisory |
| https://jira.atlassian.com/browse/CRUC-8541 | Issue Tracking Patch Vendor Advisory |
| https://jira.atlassian.com/browse/CWD-5815 | Issue Tracking Patch Vendor Advisory |
| https://jira.atlassian.com/browse/FE-7410 | Issue Tracking Patch Vendor Advisory |
| https://jira.atlassian.com/browse/JRASERVER-73897 | Issue Tracking Patch Vendor Advisory |
| https://jira.atlassian.com/browse/JSDSERVER-11863 | Issue Tracking Patch Vendor Advisory |