CVE-2026-77248: MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport

Published Sep 22, 2026
·
Updated

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the streamable HTTP transport accepts requests without a user identity and falls back to operator credentials, while uploadattachment accepts an unrestricted filepath. An unauthenticated network caller can read files available to the MCP process, upload them to an attacker-selected Jira issue or Confluence page, and retrieve the contents. The advisory traces the vulnerable input and processing flow through streamable-http, UserTokenMiddleware, uploadattachment, filepath, and getfetcher, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MCP Atlassian to a version that resolves this vulnerability.

    Fixed in 0.22.0

Event History

Sep 22, 2026
CVE Published
via MITRE·06:49 PM
Data Sourced
via MITRE·06:49 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to exploitation?

Deployments running MCP Atlassian before 0.22.0 that expose the streamable HTTP transport to network callers are exposed. The attacker does not need an authenticated user identity because the affected transport falls back to operator credentials.

2

What does an attacker need to exploit this issue?

An attacker needs network access to the affected streamable HTTP transport. They can supply a file_path to upload_attachment and select a Jira issue or Confluence page to receive the uploaded file.

3

What data can be accessed?

The attacker can read files that are available to the MCP process. The file contents can be uploaded as an attachment and then retrieved from the selected Jira issue or Confluence page.

4

What should be done to remediate the issue?

Upgrade MCP Atlassian to version 0.22.0, which fixes the issue. The vulnerable behavior affects versions prior to 0.22.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203