OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-77266

MEDIUM · CVSS 6.5 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability allows an attacker with attachment access in MCP Atlassian to exploit the upload_attachment function, enabling them to read and exfiltrate arbitrary server-local files due to insufficient path validation. This poses a risk of sensitive data exposure, particularly for organizations using Confluence and Jira prior to version 0.22.0. Organizations utilizing these products should prioritize upgrading to the fixed version to mitigate potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77266
Severity
MEDIUM
CVSS
6.5
EPSS
0.44%

Original NVD Description

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment accepts absolute paths and traversal sequences without constraining the resolved path to the server workspace. An MCP caller with attachment access can read a chosen server-local file and exfiltrate it through Jira or Confluence. The advisory traces the vulnerable input and processing flow through upload_attachment, file_path, and path traversal, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)