PT-2026-96942 · Unknown+1 · Mcp-Attlasian+2

·

CVE-2026-77247

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MCP Atlassian versions prior to 0.22.0
Description Jira and Confluence upload tools interpret caller-controlled path arguments on the MCP server and open those files before sending them as attachments. This allows a permitted client to disclose and exfiltrate host files from the server's local filesystem without requiring shell or direct filesystem access. The issue is particularly critical in remote or multi-user deployments (such as those using sse or streamable-http), where the MCP server process may have access to sensitive data like application configurations, deployment secrets, or service account tokens.
Technical details include the following vulnerable components:
  • API Endpoints: jira update issue
  • Vulnerable Parameters or Variables: file path and file paths
  • Function Names: upload attachment(), upload attachments(), and upload attachment direct()
Recommendations Update MCP Atlassian to version 0.22.0. As a temporary workaround, restrict access to the upload attachment() and upload attachments() functions to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77247
GHSA-F6PJ-QV47-G96W

Affected Products

Confluence
Jira
Mcp-Attlasian