// soc investigation 2026-03-18
SOC235 Confluence Broken Access Control 0-Day CVE-2023-22515
letsdefend High ✓ true positive
mitre/T1190mitre/T1078mitre/T1136
analyst verdict TRUE POSITIVE
✓

T1190 Exploit Public-Facing Application T1078 Valid Accounts T1136 Create Account

👤 Who

Malicious activity originated from external IP address 43.130.1.222 targeting the Confluence Data Center server (IP address 172.16.17.234).

🔎 What

The alert SOC235 Atlassian Confluence Broken Access Control 0-Day CVE-2023-22515 triggered due to exploitation attempts against a vulnerable Confluence instance. Logs confirm successful exploitation of CVE-2023-22515, allowing the attacker to bypass setup protections and create an unauthorized administrator account. HTTP logs show sequential requests using curl to access /server-info.action, followed by POST requests to /setup/setupadministrator.action and /setup/finishsetup.action, indicating completion of the setup abuse process. The server is running Confluence version 8.0.3, which is confirmed vulnerable. Threat intelligence confirms the source IP is malicious.

🕐 When

Nov 09 2023 09:47 AM

📍 Where

Target Hostname: Confluence Data Center Destination IP Address: 172.16.17.234 Source IP Address: 43.130.1.222 Affected application: Atlassian Confluence Data Center v8.0.3 Log file: C:\Program Files\Atlassian\Confluence\logs\conf_access_log.2023-11-09.log

💡 Why

The alert was triggered due to exploitation of a known critical vulnerability (CVE-2023-22515) affecting Confluence. Investigation confirmed the instance was vulnerable and the attacker successfully abused the setup functionality to create an unauthorized administrator account. This represents a confirmed compromise of a public-facing application. The incident was contained and escalated to Tier 2 for further remediation, including patching, account review, and system integrity validation.