OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-77271

HIGH · CVSS 8.8 EPSS 0.53% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability affects the MCP Atlassian server used with Confluence and Jira, where the `validate_safe_path` function defaults to the current working directory, allowing attackers to write files in this directory due to omitted base directory specifications. This can lead to unauthorized code execution when the application imports the compromised module, circumventing previous security measures. Organizations utilizing affected versions prior to 0.22.0 should prioritize upgrading to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77271
Severity
HIGH
CVSS
8.8
EPSS
0.53%

Original NVD Description

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_safe_path defaults its base directory to os.getcwd(), and affected Confluence attachment call sites omit base_dir, allowing attacker-selected writes within the working directory. This Python module overwrite can provide code execution when the application later imports the modified module, bypassing the remediation tracked as CVE-2026-27825. This issue is fixed in version 0.22.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)