URL Processing Vulnerability in MCP Atlassian for Confluence and Jira
CVE-2026-77267

8.3HIGH

Key Information:

Vendor

Sooperset

Vendor
CVE Published:
22 September 2026

What is CVE-2026-77267?

The MCP Atlassian server, part of the Atlassian ecosystem for Confluence and Jira, possesses a vulnerability that allows a malicious actor to manipulate header data for X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url. By doing so, an attacker can potentially bypass server validation mechanisms and direct internal or service metadata requests to unauthorized destinations, undermining previously implemented security measures. It is crucial to upgrade to version 0.22.0 to mitigate this risk.

Affected Version(s)

mcp-atlassian < 0.22.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.