Skip to main content
Vulnerability Database/CVE-2026-77260

CVE-2026-77260: MCP Atlassian Path Traversal Vulnerability

CVE-2026-77260 is a path traversal flaw in MCP Atlassian server that allows attackers to access sensitive host files through unconstrained file paths. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-77260 Overview

CVE-2026-77260 is a path traversal vulnerability [CWE-22] in MCP Atlassian, a Model Context Protocol (MCP) server that exposes Confluence and Jira operations to AI clients. Versions prior to 0.22.0 accept an unconstrained file_path argument in the upload_attachment implementations for both Confluence and Jira. A permitted MCP caller can supply an absolute or traversal path, causing the server to read sensitive host files and upload them as attachments to an Atlassian destination. The attacker can then retrieve those attachments through normal Atlassian APIs, completing an arbitrary file read and exfiltration chain. The issue is resolved in version 0.22.0.

Critical Impact

An authenticated MCP caller can exfiltrate arbitrary server-local files, including secrets, tokens, and configuration data, by staging them as Atlassian attachments.

Affected Products

  • MCP Atlassian (sooperset/mcp-atlassian) — Confluence integration prior to 0.22.0
  • MCP Atlassian (sooperset/mcp-atlassian) — Jira integration prior to 0.22.0
  • Any deployment exposing the upload_attachment MCP tool to callers

Discovery Timeline

  • 2026-09-22 - CVE-2026-77260 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-77260

Vulnerability Analysis

The defect lives in the upload_attachment tool handlers within src/mcp_atlassian/confluence/attachments.py and the equivalent Jira module. Both handlers accept a caller-supplied file_path string and pass it directly to filesystem primitives after normalizing it with os.path.abspath. Absolute-path normalization does not validate that the resolved path stays within an expected workspace directory. As a result, the MCP server opens any file the process can read, including /etc/passwd, cloud credential files, private keys, and application secrets.

Once the file is read, its bytes are uploaded to a Confluence page or Jira issue chosen by the caller. The attacker retrieves the attachment through the standard Atlassian download endpoint. This turns a benign-looking productivity tool into a file exfiltration primitive.

Root Cause

The root cause is missing path containment on untrusted input. The pre-patch code branched only on os.path.isabs and did not enforce a workspace boundary, allowing both absolute paths and .. traversal sequences to escape the intended upload directory.

Attack Vector

Exploitation requires an authenticated MCP session with permission to invoke upload_attachment. The attacker crafts a tool call referencing a sensitive server-local path, targets a Confluence space or Jira issue they control, and then downloads the resulting attachment through Atlassian.

python
# Vulnerable pre-patch flow vs. hardened flow in
# src/mcp_atlassian/confluence/attachments.py

# Before (vulnerable):
#     if not os.path.isabs(file_path):
#         file_path = os.path.abspath(file_path)

# After (patched in v0.22.0):
#     # Confine the upload source to the workspace before it is read: reject
#     # traversal/absolute paths that escape CWD (arbitrary file read /
#     # exfiltration via a caller-supplied file_path).
#     file_path = str(validate_safe_path(file_path))

# Check if file exists
if not os.path.exists(file_path):
    return {"success": False, "error": "File not found"}

Source: GitHub Commit b0417334

Detection Methods for CVE-2026-77260

Indicators of Compromise

  • Attachment upload events in Confluence or Jira audit logs where filenames match sensitive host paths such as passwd, id_rsa, .env, or credentials.
  • MCP server logs showing upload_attachment invocations with file_path values that are absolute or contain .. segments.
  • Outbound reads by the MCP process against directories outside its intended workspace.

Detection Strategies

  • Correlate MCP tool-call telemetry with filesystem access syscalls to flag reads of files that never appear in normal upload_attachment workflows.
  • Alert on Confluence or Jira attachments created by service accounts tied to MCP integrations when the attachment name or MIME type deviates from expected content types.
  • Deploy path-traversal detection rules against structured MCP request logs, looking for file_path values starting with /, C:\, or containing ...

Monitoring Recommendations

  • Enable verbose logging on the MCP Atlassian server and forward records to a centralized analytics pipeline.
  • Monitor Atlassian audit logs for spikes in attachment creation by MCP-linked accounts.
  • Track process-level file access patterns for the MCP runtime and baseline against the declared workspace directory.

How to Mitigate CVE-2026-77260

Immediate Actions Required

  • Upgrade MCP Atlassian to version 0.22.0 or later, which introduces validate_safe_path for upload_attachment handlers.
  • Rotate any credentials, API tokens, or private keys that resided on hosts running vulnerable MCP Atlassian deployments.
  • Review Confluence and Jira attachments created by MCP service accounts and remove any that contain sensitive host data.

Patch Information

The fix is delivered in MCP Atlassian v0.22.0 via Pull Request #1448 and commit b0417334. Details are published in GHSA-f4p7-qx46-wc5j. The patch introduces validate_safe_path, which rejects absolute paths and traversal sequences that escape the current working directory.

Workarounds

  • Restrict the MCP Atlassian process to a dedicated, low-privilege user with filesystem access limited to a sandboxed workspace directory.
  • Gate the upload_attachment tool behind an allowlist of MCP callers until upgrade is possible.
  • Run the MCP server inside a container or chroot with no access to secrets, credential stores, or application configuration files.
bash
# Upgrade MCP Atlassian to the patched release
pip install --upgrade "mcp-atlassian>=0.22.0"

# Verify installed version
python -c "import importlib.metadata; print(importlib.metadata.version('mcp-atlassian'))"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.