File Upload Vulnerability in Atlassian's Confluence and Jira
CVE-2026-77260

8.3HIGH

Key Information:

Vendor

Sooperset

Vendor
CVE Published:
22 September 2026

What is CVE-2026-77260?

The MCP Atlassian server facilitates file uploads for Confluence and Jira. Prior to version 0.22.0, it erroneously allows users to provide unrestricted file paths, enabling the upload of server-local files. This flaw permits authorized MCP callers to access and retrieve sensitive files from the server environment. The vulnerability has been traced through specific code paths, revealing inadequate input validation during the file upload process. This issue has been remediated in version 0.22.0.

Affected Version(s)

mcp-atlassian < 0.22.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.