Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-77266

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment accepts absolute paths and traversal sequences without constraining the resolved path to the server workspace. An MCP caller with attachment access can read a chosen server-local file and exfiltrate it through Jira or Confluence. The advisory traces the vulnerable input and processing flow through upload_attachment, file_path, and path traversal, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 40.6%
CVSS Severity
CVSS v3 Score 6.5


Contact Us

Shodan ® - All rights reserved