OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-77259

HIGH · CVSS 7.7 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability allows attackers to upload sensitive server-local files, such as environment files and credentials, to Confluence pages without proper path validation. This could lead to unauthorized access to sensitive information, posing a significant risk to organizations using affected versions of Atlassian Confluence and Jira. Organizations utilizing these products should prioritize upgrading to version 0.22.0 or later to mitigate this high-severity threat.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77259
Severity
HIGH
CVSS
7.7
EPSS
0.41%

Original NVD Description

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment opens a caller-selected server-local file without checking that the resolved path remains in the workspace. A caller can upload environment files, credentials, or other readable host data to a Confluence page and retrieve it through Atlassian. The advisory traces the vulnerable input and processing flow through confluence_upload_attachment, file_path, and open(file_path, "rb"), which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)