Data Exposure Vulnerability in Confluence and Jira by Atlassian
CVE-2026-77258

7.7HIGH

Key Information:

Vendor

Sooperset

Vendor
CVE Published:
22 September 2026

What is CVE-2026-77258?

The MCP Atlassian server, utilized by Atlassian products like Confluence and Jira, has a vulnerability that allows an authorized caller to upload a file without proper restrictions to the file path. This flaw enables a potential exposure of server-readable data, which could be misused by malicious actors. The issue arises in the upload_attachment function in the attachments.py file, where the input is not adequately validated. The vulnerability is addressed in version 0.22.0, which includes necessary security improvements to prevent unauthorized file uploads.

Affected Version(s)

mcp-atlassian < 0.22.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.