File Upload Vulnerability in Atlassian's Confluence and Jira
CVE-2026-77260
8.3HIGH
What is CVE-2026-77260?
The MCP Atlassian server facilitates file uploads for Confluence and Jira. Prior to version 0.22.0, it erroneously allows users to provide unrestricted file paths, enabling the upload of server-local files. This flaw permits authorized MCP callers to access and retrieve sensitive files from the server environment. The vulnerability has been traced through specific code paths, revealing inadequate input validation during the file upload process. This issue has been remediated in version 0.22.0.
Affected Version(s)
mcp-atlassian < 0.22.0
