OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-77248 (CVSS 8.6)

NVD · officialPublished Sep 22, 2026Risk 37/100EPSS 0.4%

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the streamable HTTP transport accepts requests without a user identity and falls back to operator credentials, while upload_attachment accepts an unrestricted file_path. An unauthenticated network caller can read files available to the MCP process, upload them to an attacker-selected Jira issue or Confluence page, and retrieve the contents. The advisory traces the vulnerable input and processing flow through streamable-http, UserTokenMiddleware, upload_attachment, file_path, and _get_fetcher, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

CVSS
8.6
AV:NetworkAC:LowPR:NoneUI:NoneC:HighI:NoneA:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source