Model Context Protocol Vulnerability in Atlassian Confluence and Jira Products
CVE-2026-77265
What is CVE-2026-77265?
The Model Context Protocol (MCP) server for Atlassian products, specifically Confluence and Jira, prior to version 0.22.0, is vulnerable to a security issue that allows an unauthenticated attacker to exploit DNS rebinding. This vulnerability could enable the attacker to craft header-supplied URLs that mislead the HTTP client into connecting to internal resources instead of the intended external address. Through this flaw, internal metadata services may be exposed to unauthorized access by leveraging the processing flow of certain entry points, including X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url, which are inadequately validated before the connection is established. The issue has been addressed in the latest release, ensuring that proper validation mechanisms are in place to thwart such attacks.
Affected Version(s)
mcp-atlassian < 0.22.0
