CVE-2022-26133
Estado: ModificadaCrítica (9.8)—
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 70%
- Percentil entre todas las CVEs puntuadas: 99
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-502
- CWE-502
Referencias
- https://confluence.atlassian.com/security/multiple-products-security-advisory-hazelcast-vulnerable-to-remote-code-execution-cve-2016-10750-1116292387.html
- https://jira.atlassian.com/browse/BSERV-13173
- https://confluence.atlassian.com/security/multiple-products-security-advisory-hazelcast-vulnerable-to-remote-code-execution-cve-2016-10750-1116292387.html
- https://jira.atlassian.com/browse/BSERV-13173
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-26133",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-26133",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-10-03T14:41:09.024921Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@atlassian.com",
"affectedData": [
{
"vendor": "Atlassian",
"product": "Bitbucket Data Center",
"versions": [
{
"status": "affected",
"version": "5.14.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "7.6.14",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.7.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "7.17.6",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.18.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "7.18.4",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.19.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "7.19.4",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.20.0"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:atlassian:bitbucket_data_center:*:*:*:*:*:*:*:*"
],
"vendor": "atlassian",
"product": "bitbucket_data_center",
"versions": [
{
"status": "affected",
"version": "5.14.0",
"lessThan": "7.6.14",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.7.0",
"lessThan": "7.17.6",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.18.0",
"lessThan": "7.18.4",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.19.0",
"lessThan": "7.19.4",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:atlassian:bitbucket_data_center:7.20.0:*:*:*:*:*:*:*"
],
"vendor": "atlassian",
"product": "bitbucket_data_center",
"versions": [
{
"status": "affected",
"version": "7.20.0"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2022-04-20T19:15:08.157",
"references": [
{
"url": "https://confluence.atlassian.com/security/multiple-products-security-advisory-hazelcast-vulnerable-to-remote-code-execution-cve-2016-10750-1116292387.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "security@atlassian.com"
},
{
"url": "https://jira.atlassian.com/browse/BSERV-13173",
"tags": [
"Vendor Advisory"
],
"source": "security@atlassian.com"
},
{
"url": "https://confluence.atlassian.com/security/multiple-products-security-advisory-hazelcast-vulnerable-to-remote-code-execution-cve-2016-10750-1116292387.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://jira.atlassian.com/browse/BSERV-13173",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-502"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-502"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization."
},
{
"lang": "es",
"value": "SharedSecretClusterAuthenticator en Atlassian Bitbucket Data Center versiones 5.14.0 y posteriores anteriores a 7.6.14, versiones 7.7.0 y posteriores anteriores a 7.17.6, versiones 7.18.0 y posteriores anteriores a 7.18.4, versiones 7.19.0 y posteriores anteriores a 7.19.4, y versión 7.20.0, permiten a un atacante remoto no autenticado ejecutar código arbitrario por medio de una deserialización de Java"
}
],
"lastModified": "2026-06-17T04:34:44.773",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:atlassian:bitbucket_data_center:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1E530A6D-88FB-4E3F-8C2D-03298F4D3DC8",
"versionEndExcluding": "7.6.14",
"versionStartIncluding": "5.14.0"
},
{
"criteria": "cpe:2.3:a:atlassian:bitbucket_data_center:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C51DBE72-FBFC-49ED-B81D-A9BFD76FFDE1",
"versionEndExcluding": "7.17.6",
"versionStartIncluding": "7.7.0"
},
{
"criteria": "cpe:2.3:a:atlassian:bitbucket_data_center:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "05ACFD2B-BE5A-4D7A-831C-0E1AF803DCAD",
"versionEndExcluding": "7.18.4",
"versionStartIncluding": "7.18.0"
},
{
"criteria": "cpe:2.3:a:atlassian:bitbucket_data_center:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16F97B63-963E-440E-A671-E87FBB658504",
"versionEndExcluding": "7.19.4",
"versionStartIncluding": "7.19.0"
},
{
"criteria": "cpe:2.3:a:atlassian:bitbucket_data_center:7.20.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF9D614F-F4C6-4AC5-88E1-A979A5DDE654"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@atlassian.com"
}