Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-77258

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path and opens the selected server-local file without restricting it to the workspace. A permitted Confluence MCP caller can upload the file as an attachment and disclose data readable by the server process. This issue is fixed in version 0.22.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 23.3%
CVSS Severity
CVSS v3 Score 7.7
Products affected by CVE-2026-77258


Contact Us

Shodan ® - All rights reserved