Data Exposure Vulnerability in Confluence and Jira by Atlassian
CVE-2026-77258
7.7HIGH
What is CVE-2026-77258?
The MCP Atlassian server, utilized by Atlassian products like Confluence and Jira, has a vulnerability that allows an authorized caller to upload a file without proper restrictions to the file path. This flaw enables a potential exposure of server-readable data, which could be misused by malicious actors. The issue arises in the upload_attachment function in the attachments.py file, where the input is not adequately validated. The vulnerability is addressed in version 0.22.0, which includes necessary security improvements to prevent unauthorized file uploads.
Affected Version(s)
mcp-atlassian < 0.22.0
