Skip to main content
Vulnerability Database/CVE-2026-77248

CVE-2026-77248: MCP Atlassian Path Traversal Vulnerability

CVE-2026-77248 is a path traversal vulnerability in MCP Atlassian server that allows unauthenticated attackers to read and upload files to Jira or Confluence. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-77248 Overview

MCP Atlassian is a Model Context Protocol (MCP) server that bridges AI clients with Atlassian Confluence and Jira. Versions prior to 0.22.0 contain two chained weaknesses in the streamable HTTP transport. The transport accepts requests without a user identity and falls back to operator credentials, while the upload_attachment tool accepts an unrestricted file_path. An unauthenticated network caller can read files accessible to the MCP process, upload them as attachments to an attacker-controlled Jira issue or Confluence page, and then retrieve the contents. The issue is classified as a path traversal weakness [CWE-22] and is fixed in version 0.22.0.

Critical Impact

Unauthenticated remote attackers can exfiltrate arbitrary files readable by the MCP Atlassian process by staging them as Confluence or Jira attachments.

Affected Products

  • MCP Atlassian server (sooperset/mcp-atlassian) prior to 0.22.0
  • Deployments using the streamable HTTP transport with operator credentials
  • Integrations bridging Confluence and Jira to Model Context Protocol clients

Discovery Timeline

  • 2026-09-22 - CVE-2026-77248 published to NVD
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-77248

Vulnerability Analysis

The vulnerability chains a missing authentication check with an unvalidated file path parameter. The advisory identifies the affected code paths as streamable-http, UserTokenMiddleware, upload_attachment, file_path, and _get_fetcher. When a request arrives over the streamable HTTP transport without a user token, UserTokenMiddleware does not reject it. Instead, _get_fetcher returns a client authenticated with the server operator's credentials.

The upload_attachment tool then reads the caller-supplied file_path directly from the local filesystem. Because the path is neither confined to a workspace nor checked for traversal sequences, an attacker can specify absolute paths or .. sequences to reach sensitive files. The uploaded attachment is subsequently downloadable through the destination Jira issue or Confluence page, completing the exfiltration primitive.

Root Cause

Two defects combine to produce the impact. First, the streamable HTTP transport treats unauthenticated callers as trusted and falls back to operator credentials. Second, upload_attachment performs no path canonicalization or workspace confinement before opening the file. This maps to [CWE-22] Improper Limitation of a Pathname to a Restricted Directory.

Attack Vector

An attacker with network reach to the MCP Atlassian streamable HTTP endpoint sends an upload_attachment request specifying an absolute file path such as a credential file, environment file, or SSH key readable by the MCP process. The server reads the file using operator credentials, uploads it to a Jira issue or Confluence page the attacker controls, and the attacker retrieves the attachment through standard Atlassian APIs.

python
# Patch: src/mcp_atlassian/confluence/attachments.py
# Before: relative paths were promoted to absolute paths with no validation
# After: paths are confined to the workspace via validate_safe_path()

try:
    # Confine the upload source to the workspace before it is read: reject
    # traversal/absolute paths that escape CWD (arbitrary file read /
    # exfiltration via a caller-supplied file_path).
    file_path = str(validate_safe_path(file_path))

    # Check if file exists
    if not os.path.exists(file_path):
        ...
# Source: https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460

Detection Methods for CVE-2026-77248

Indicators of Compromise

  • Attachment upload events in Jira or Confluence audit logs originating from the MCP operator account for files not associated with normal user workflows.
  • Attachments whose filenames or contents match host paths such as /etc/passwd, .env, id_rsa, or application configuration files.
  • Streamable HTTP requests to the MCP Atlassian endpoint lacking user identity headers or bearer tokens.

Detection Strategies

  • Alert on invocations of upload_attachment where file_path contains absolute paths, .. sequences, or references outside the intended workspace directory.
  • Correlate MCP process file-read telemetry with subsequent outbound HTTP requests to Atlassian Cloud or Data Center endpoints.
  • Baseline the operator service account's normal attachment activity in Jira and Confluence and flag deviations in volume, target space, or filename patterns.

Monitoring Recommendations

  • Enable verbose logging in the MCP Atlassian server for UserTokenMiddleware decisions and upload_attachment calls, and forward to a central log store.
  • Monitor filesystem access by the MCP Atlassian process for reads outside its expected working directory.
  • Track newly created Jira issues and Confluence pages that immediately receive attachments from the operator account.

How to Mitigate CVE-2026-77248

Immediate Actions Required

  • Upgrade MCP Atlassian to version 0.22.0 or later, which introduces validate_safe_path() and hardens the streamable HTTP transport.
  • Rotate any credentials, tokens, or secrets that were readable by the MCP Atlassian process on affected hosts.
  • Audit Jira and Confluence attachments created by the MCP operator account since deployment for unauthorized file uploads.

Patch Information

The fix is available in the GitHub Release v0.22.0. The patch is described in GitHub Pull Request #1448 and GitHub Commit b041733. Full technical context is documented in GitHub Security Advisory GHSA-cc5h-2pwp-pvcc.

Workarounds

  • Restrict network access to the MCP Atlassian streamable HTTP endpoint using firewall rules or a reverse proxy that enforces authentication before requests reach the server.
  • Run the MCP Atlassian process as an unprivileged user in a container or chroot with only the minimum files required for operation mounted read-only.
  • Scope the operator Atlassian API token to the minimum required Jira projects and Confluence spaces to reduce the exfiltration surface.
bash
# Upgrade to the patched release
pip install --upgrade "mcp-atlassian>=0.22.0"

# Verify installed version
pip show mcp-atlassian | grep -i version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.