Skip to main content

CVE detail

CVE-2022-36804

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

CVSS 8.8 · HighBuzz score 65.1KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 65.1

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 22.0 · diversity 11.0 · KEV 25.0 · OTX 0.0 · PoC 7.1
Mention score
22.0
8 evidence mentions in the snapshot
Diversity score
11.0
5 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
7.1
1 repos · best confidence 0.99
Best PoC traction
12
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
8 source links · newest first
  • The cybercrime underground has long functioned as an open market where sellers of products and services are paired with buyers and contractors. One of the most valuable commodities on this market are stolen credentials since they can provide attackers with access into networks, databases, and other assets owned by organizations. It’s no surprise to see […]

    newswww.csoonline.comMar 10, 2023, 1:06 AM
  • The United States Cybersecurity and Infrastructure Security Agency (CISA) is warning of the active exploitation of a recent Atlassian Bitbucket vulnerability and two Microsoft Exchange zero-days. Atlassian Bitbucket is a Git-based repository management solution that provides source code hosting and sharing capabilities.

    newswww.securityweek.comOct 3, 2022, 10:49 AM
  • On September 29, 2022 the Cybersecurity & Infrastructure Security Agency (CISA) added three vulnerabilities to the catalog of known to be exploited…

    newswww.malwarebytes.comOct 2, 2022, 5:00 PM
  • CISA added a recently disclosed flaw in Atlassian Bitbucket Server, tracked as CVE-2022-36804, to its Known Exploited Vulnerabilities Catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) this week added a recently disclosed critical vulnerability in Atlassian’s Bitbucket Server and Data Center to its Known Exploited Vulnerabilities Catalog. According to Binding Operational Directive (BOD) 22-01: Reducing the Significant […]

    newssecurityaffairs.comOct 1, 2022, 5:02 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: US-based CISOs get nearly $1 million per year The role of the Chief Information Security Officer (CISO) is a relatively new senior-level executive position within most organizations, and is still evolving. To find out how current CISOs landed in that role, their aspirations, the compensation they receive, and which risks they face and responsibilities they shoulder, analysts with international executive … More →

    newswww.helpnetsecurity.comSep 4, 2022, 8:00 AM
  • A critical vulnerability (CVE-2022-36804) in Atlassian Bitbucket Server and Data Center could be exploited by unauthorized attackers to execute malicious code on vulnerable instances. About CVE-2022-36804 Bitbucket Server and Data Center are used by software developers around the world for source code revision control, management and hosting. CVE-2022-36804 is a command injection vulnerability in multiple API endpoints of Bitbucket Server and Data Center. “An attacker with access to a public repository or with read permissions … More →

    newswww.helpnetsecurity.comAug 29, 2022, 11:03 AM
  • Atlassian addressed a critical vulnerability in Bitbucket Server and Data Center that could lead to malicious code execution on vulnerable instances. Atlassian fixed a critical flaw in Bitbucket Server and Data Center, tracked as CVE-2022-36804 (CVSS score 9.9), that could be explored to execute malicious code on vulnerable installs The flaw is a command injection vulnerability that can be exploited via […]

    newssecurityaffairs.comAug 26, 2022, 11:08 PM
  • Atlassian’s security response team has issued an urgent advisory to warn of a critical command injection flaw in its Bitbucket Server and Data Center product. The vulnerability carries a CVSS severity score of 9.9 out of 10 and can be exploited remotely to launch code execution attacks, Atlassian said.

    newswww.securityweek.comAug 26, 2022, 7:26 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.99 · max 12 stars
  • sh4den/CVE-2022-36804High confidence
    githubDiscovery source unavailable12 starsDiscovered Jul 9, 2026, 1:19 AM

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-52891

    Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for…

    CVSS 9.9 · Critical
    3 mentions
  • CVE-2026-54088

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, the Hook Authentication f…

    CVSS 9.3 · Critical
  • CVE-2026-40079

    Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command…

    CVSS 8.6 · High
    2 mentions
  • CVE-2026-54686

    Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepted certain state-mutating terminal lifecycle hooks fro…

    CVSS 4.3 · Medium
    3 mentions
  • CVE-2026-44712

    pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such as $(id>/tmp/rce) in the config causes root RCE when pamusb-…

    CVSS 8.2 · High
    1 mention
  • CVE-2026-46483

    Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz…

    CVSS 3.6 · Low
    4 mentions