Skip to main content
Vulnerability Database/CVE-2026-77246

CVE-2026-77246: MCP Atlassian Path Traversal Vulnerability

CVE-2026-77246 is a path traversal flaw in MCP Atlassian that allows attackers to upload local files to attacker-controlled endpoints. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-77246 Overview

CVE-2026-77246 affects MCP Atlassian, a Model Context Protocol (MCP) server that bridges AI clients to Atlassian Confluence and Jira. Versions prior to 0.22.0 accept unauthenticated HTTP transport requests when READ_ONLY_MODE=false. An attacker can supply the X-Atlassian-Confluence-Url header to redirect attachment uploads to an attacker-controlled host. Combined with a caller-supplied file_path, this enables server-local file exfiltration through confluence_upload_attachment or its Jira counterpart in src/mcp_atlassian/jira/attachments.py. The issue is classified under [CWE-22] path traversal and is fixed in version 0.22.0.

Critical Impact

Unauthenticated adjacent-network attackers can read and exfiltrate arbitrary server-local files by coercing the MCP process to upload them to an attacker-selected Atlassian endpoint.

Affected Products

  • MCP Atlassian server versions prior to 0.22.0
  • Deployments running the HTTP transport with READ_ONLY_MODE=false
  • Instances where MCP_ALLOWED_URL_DOMAINS permits attacker-reachable hostnames

Discovery Timeline

  • 2026-09-22 - CVE-2026-77246 published to NVD
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-77246

Vulnerability Analysis

MCP Atlassian exposes tool calls that let clients upload files as attachments to Confluence or Jira. When the HTTP transport is enabled without authentication enforcement, the server accepts requests that lack an Authorization identity. The server also honors Atlassian service headers supplied by the caller, including X-Atlassian-Confluence-Url. An attacker chooses either a fully public hostname or one permitted by MCP_ALLOWED_URL_DOMAINS. The MCP process then reads the file located at the caller-supplied file_path and transmits it to the attacker-chosen endpoint. This chains a Server-Side Request Forgery (SSRF) primitive with a path traversal read primitive, producing arbitrary file disclosure from the host running the MCP server.

Root Cause

Two defects combine. First, the HTTP transport does not require an authenticated identity before dispatching attachment tool calls. Second, the attachment handler in src/mcp_atlassian/confluence/attachments.py and the Jira variant convert relative paths to absolute paths without validating that the target stays within the workspace. Neither the target URL nor the file path is confined to a safe boundary.

Attack Vector

An adjacent-network attacker sends an HTTP request to the MCP endpoint invoking confluence_upload_attachment or the Jira attachment tool. The request sets X-Atlassian-Confluence-Url to an attacker-controlled host and passes a file_path such as /etc/passwd or a Kubernetes service account token path. The MCP process reads the file and POSTs it to the attacker endpoint.

python
            return {"success": False, "error": "No file path provided"}

        try:
            # Confine the upload source to the workspace before it is read: reject
            # traversal/absolute paths that escape CWD (arbitrary file read /
            # exfiltration via a caller-supplied file_path).
            file_path = str(validate_safe_path(file_path))

            # Check if file exists
            if not os.path.exists(file_path):

Source: GitHub Commit b041733. The patch replaces unchecked absolute-path resolution with validate_safe_path, which rejects traversal or absolute paths that escape the current working directory.

Detection Methods for CVE-2026-77246

Indicators of Compromise

  • Outbound HTTP POST requests from the MCP Atlassian process to hostnames not belonging to your Atlassian tenant.
  • Inbound MCP HTTP transport requests carrying X-Atlassian-Confluence-Url headers referencing external domains.
  • Attachment tool invocations where file_path references absolute paths outside the workspace, such as /etc/, /root/, or /var/run/secrets/.

Detection Strategies

  • Inspect MCP server access logs for unauthenticated calls to confluence_upload_attachment or the Jira attachment endpoint in src/mcp_atlassian/jira/attachments.py.
  • Alert when the process reads sensitive host paths shortly before egress to a non-Atlassian domain.
  • Correlate X-Atlassian-* header values against an allowlist of expected tenant URLs.

Monitoring Recommendations

  • Forward MCP transport, process, and network telemetry to a centralized data lake for correlation.
  • Monitor changes to the READ_ONLY_MODE and MCP_ALLOWED_URL_DOMAINS environment variables in deployment manifests.
  • Track egress destinations from AI tool-execution workloads and baseline expected Atlassian endpoints.

How to Mitigate CVE-2026-77246

Immediate Actions Required

  • Upgrade MCP Atlassian to version 0.22.0 or later.
  • Set READ_ONLY_MODE=true on any HTTP transport deployment that does not require write operations.
  • Restrict MCP_ALLOWED_URL_DOMAINS to the exact tenant hostnames used by your Atlassian instances.
  • Require an authenticated identity on all MCP HTTP transport requests through a reverse proxy or gateway.

Patch Information

The fix is included in GitHub Release v0.22.0, delivered through Pull Request #1448 and commit b041733. The patch adds validate_safe_path enforcement in the Confluence and Jira attachment handlers, hardens transport authorization, and adds SSRF filtering. Details are documented in GHSA-wv8v-v4c5-v75j.

Workarounds

  • Deploy the MCP server behind a network policy that blocks egress to all destinations outside approved Atlassian tenants.
  • Run the MCP process as a low-privileged user in a container with a minimal filesystem to reduce readable sensitive files.
  • Strip client-supplied X-Atlassian-* headers at an upstream proxy until upgrade is complete.
bash
# Configuration example
export READ_ONLY_MODE=true
export MCP_ALLOWED_URL_DOMAINS="your-tenant.atlassian.net"
# Enforce authentication at the reverse proxy layer before requests reach MCP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.