CVE detail
CVE-2022-36804
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 11.0 · KEV 25.0 · OTX 0.0 · PoC 7.1
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
The cybercrime underground has long functioned as an open market where sellers of products and services are paired with buyers and contractors. One of the most valuable commodities on this market are stolen credentials since they can provide attackers with access into networks, databases, and other assets owned by organizations. It’s no surprise to see […]
newswww.csoonline.comMar 10, 2023, 1:06 AMThe United States Cybersecurity and Infrastructure Security Agency (CISA) is warning of the active exploitation of a recent Atlassian Bitbucket vulnerability and two Microsoft Exchange zero-days. Atlassian Bitbucket is a Git-based repository management solution that provides source code hosting and sharing capabilities.
newswww.securityweek.comOct 3, 2022, 10:49 AM- Actively exploited vulnerability in Bitbucket Server and Data CenterMalwarebytes Labs
On September 29, 2022 the Cybersecurity & Infrastructure Security Agency (CISA) added three vulnerabilities to the catalog of known to be exploited…
newswww.malwarebytes.comOct 2, 2022, 5:00 PM - CISA adds Atlassian Bitbucket Server flaw to its Known Exploited Vulnerabilities CatalogSecurity Affairs
CISA added a recently disclosed flaw in Atlassian Bitbucket Server, tracked as CVE-2022-36804, to its Known Exploited Vulnerabilities Catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) this week added a recently disclosed critical vulnerability in Atlassian’s Bitbucket Server and Data Center to its Known Exploited Vulnerabilities Catalog. According to Binding Operational Directive (BOD) 22-01: Reducing the Significant […]
newssecurityaffairs.comOct 1, 2022, 5:02 PM - Week in review: CISOs’ earnings per year, Atlassian Bitbucket Server and Data Center flawHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: US-based CISOs get nearly $1 million per year The role of the Chief Information Security Officer (CISO) is a relatively new senior-level executive position within most organizations, and is still evolving. To find out how current CISOs landed in that role, their aspirations, the compensation they receive, and which risks they face and responsibilities they shoulder, analysts with international executive … More →
newswww.helpnetsecurity.comSep 4, 2022, 8:00 AM - Patch critical flaw in Atlassian Bitbucket Server and Data Center! (CVE-2022-36804)Help Net Security
A critical vulnerability (CVE-2022-36804) in Atlassian Bitbucket Server and Data Center could be exploited by unauthorized attackers to execute malicious code on vulnerable instances. About CVE-2022-36804 Bitbucket Server and Data Center are used by software developers around the world for source code revision control, management and hosting. CVE-2022-36804 is a command injection vulnerability in multiple API endpoints of Bitbucket Server and Data Center. “An attacker with access to a public repository or with read permissions … More →
newswww.helpnetsecurity.comAug 29, 2022, 11:03 AM - Critical flaw impacts Atlassian Bitbucket Server and Data CenterSecurity Affairs
Atlassian addressed a critical vulnerability in Bitbucket Server and Data Center that could lead to malicious code execution on vulnerable instances. Atlassian fixed a critical flaw in Bitbucket Server and Data Center, tracked as CVE-2022-36804 (CVSS score 9.9), that could be explored to execute malicious code on vulnerable installs The flaw is a command injection vulnerability that can be exploited via […]
newssecurityaffairs.comAug 26, 2022, 11:08 PM Atlassian’s security response team has issued an urgent advisory to warn of a critical command injection flaw in its Bitbucket Server and Data Center product. The vulnerability carries a CVSS severity score of 9.9 out of 10 and can be exploited remotely to launch code execution attacks, Atlassian said.
newswww.securityweek.comAug 26, 2022, 7:26 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.99 · max 12 stars
- sh4den/CVE-2022-36804High confidencegithubDiscovery source unavailable12 starsDiscovered Jul 9, 2026, 1:19 AM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-52891CVSS 9.9 · Critical
Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for…
- CVE-2026-54088CVSS 9.3 · Critical
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, the Hook Authentication f…
- CVE-2026-40079CVSS 8.6 · High
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command…
- CVE-2026-54686CVSS 4.3 · Medium
Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepted certain state-mutating terminal lifecycle hooks fro…
- CVE-2026-44712CVSS 8.2 · High
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such as $(id>/tmp/rce) in the config causes root RCE when pamusb-…
- CVE-2026-46483CVSS 3.6 · Low
Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz…