Join our Newsletter — 33% off our NHI Course

What are the signs that a Confluence instance is being abused through CVE-2023-22518?

Observable signs include repeated POST requests to setup restore endpoints, unexpected progress polling after setup activity, creation of a malicious webshell plugin, and new administrative accounts that were not approved. On the endpoint side, responders may also see base64 decoded download scripts, unusual PowerShell activity, and child processes that retrieve payloads from unfamiliar IP addresses.

How the compromise usually shows up

The clearest early clue is activity against Confluence setup and restore endpoints that should not be happening in a live, already-configured instance. Repeated POSTs, followed by unexpected progress polling, often indicate someone is driving the vulnerable setup path to reach code execution or persistence rather than performing normal administration.

Once that path is abused, defenders may see a webshell plugin appear or change in place, because the attacker needs a durable way to issue commands after the initial exploit. That is why this issue should be treated as an intrusion pattern, not just a product bug. For baseline vulnerability context, the CVE Program and the NIST National Vulnerability Database are the canonical references.

When those web-facing indicators are present together with a new administrative account that was not approved, the most likely interpretation is that the attacker has moved beyond probing and has gained actionable control. In practice, that account creation is often paired with post-exploitation steps such as privilege expansion, plugin tampering, or lateral movement through internal tooling.

Host and endpoint signs that matter most

Endpoint telemetry often gives the strongest confirmation that the Confluence exploit has been converted into hands-on-keyboard activity. Base64-decoded download scripts, unusual PowerShell execution, and child processes reaching out to unfamiliar IP addresses are classic signs that the attacker is staging payloads or fetching follow-on tools after initial access.

These signals are especially important because they separate a merely vulnerable server from an actively abused one. A vulnerable Confluence instance may be silent; an abused one usually leaves an execution trail that links the web request to operating-system activity, which is what responders need to scope impact and decide whether containment must extend beyond the application server.

Watch for parent-child process chains that do not fit your normal application baseline, particularly when the parent is a web process and the child is a shell, script interpreter, or archive utility. If those processes also contact external infrastructure that is not part of your approved update or integration paths, treat the event as likely malicious until proven otherwise.

What the full attack chain is telling you

Abuse of CVE-2023-22518 is usually not a single-action event. The sequence of setup endpoint access, progress checks, payload retrieval, account creation, and plugin deployment suggests a campaign that is trying to establish persistence and preserve operational flexibility. That matters because the initial exploit tells you only that access was possible; the follow-on behavior tells you what the attacker can now do.

The practical conclusion is that detections should correlate web logs, application audit data, and endpoint telemetry rather than relying on any one artifact. A single suspicious POST may be noise, but a cluster of setup activity followed by a webshell and account changes is a strong abuse pattern.

The strongest external references for the underlying vulnerability remain the CVE Program and the NIST National Vulnerability Database. For response teams that want an attack-path lens, MITRE ATT&CK Enterprise Matrix is useful for mapping the observed behavior to credential access, persistence, and lateral movement patterns.

Risk and Threat Considerations

When CVE-2023-22518 is being abused, the risk is not just service compromise, it is post-exploitation control of a collaboration platform that often has broad internal visibility and trust. Once an attacker can create accounts, plant a webshell, or pull payloads from the host, the platform can become a foothold for further access across the environment.

Failure mechanism: The vulnerable setup workflow is being driven after deployment, which can let an attacker reach code execution, establish persistence, and then use the application server to launch additional tools or credentials theft.

Impact: Expect account abuse, unauthorized content or plugin changes, internal reconnaissance, and possible lateral movement from a trusted application server into adjacent systems.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 SI-4 — System Monitoring Abuse detection here depends on correlating web, host, and network telemetry.
Recommendation — Correlate web and endpoint telemetry to detect exploitation and persistence.
MITRE ATT&CK T1190 — Exploit Public-Facing Application The observed setup-endpoint abuse is a public-facing application exploitation pattern.
Recommendation — Map suspicious Confluence traffic to T1190 and hunt for post-exploitation activity.

Practitioner Guidance

What to verify: Confirm whether the instance received setup-restore POSTs after it should have been fully initialized, and check whether any account creation, plugin installation, or admin change lines up with those requests. If the timing fits, assume the event chain is connected until disproven.

What to prioritize: Correlate web logs with endpoint process creation and network connections before you spend time on cosmetic changes in the UI. The highest-value evidence is the bridge between the HTTP trigger and the host execution that followed it.

Practitioner takeaway: For this CVE, the decisive question is not only whether the instance was vulnerable, but whether web exploitation already turned into persistent host control, because that changes the response from patching to full compromise handling.