Skip to main content
Vulnerability Database/CVE-2026-77262

CVE-2026-77262: MCP Atlassian Path Traversal Vulnerability

CVE-2026-77262 is a path traversal flaw in MCP Atlassian that allows attackers to upload arbitrary server-readable files to Confluence. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-77262 Overview

CVE-2026-77262 is a path traversal vulnerability [CWE-22] in MCP Atlassian, a Model Context Protocol (MCP) server for Atlassian Confluence and Jira. Versions prior to 0.22.0 expose the confluence_upload_attachment tool, which accepts an attacker-controlled file_path parameter without applying workspace path restrictions. A caller can traverse outside the intended workspace and upload arbitrary server-readable files to Confluence, enabling data exfiltration through the attachment channel. The issue is fixed in version 0.22.0 through a validate_safe_path control.

Critical Impact

A remote caller of the MCP server can read any file accessible to the server process and exfiltrate it as a Confluence attachment, exposing secrets, tokens, and configuration data.

Affected Products

  • MCP Atlassian versions prior to 0.22.0
  • Deployments exposing the confluence_upload_attachment MCP tool
  • Confluence integrations relying on MCP Atlassian for file handling

Discovery Timeline

  • 2026-09-22 - CVE-2026-77262 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-77262

Vulnerability Analysis

MCP Atlassian exposes confluence_upload_attachment as an MCP tool that reads a local file and uploads it to a Confluence page. Before version 0.22.0, the handler accepted the caller-supplied file_path value and converted relative paths to absolute paths using os.path.abspath. No validation confined the resolved path to the server workspace.

An attacker interacting with the MCP server can supply an absolute path such as /etc/passwd or a traversal sequence such as ../../../root/.ssh/id_rsa. The server reads the target file and uploads its contents to a Confluence page under the attacker's control. This converts a benign attachment API into an arbitrary file read primitive whose output is delivered through Confluence.

The advisory links this bug to CVE-2026-27825, a prior download-side path traversal. The earlier fix added a workspace restriction on downloads but did not extend the same guard to the upload path.

Root Cause

The root cause is missing path canonicalization and workspace confinement in the upload handler. The pre-patch code contained only:

python
# Convert to absolute path if relative
if not os.path.isabs(file_path):
    file_path = os.path.abspath(file_path)

Source: GitHub Commit b041733

This logic normalizes the path but does not reject values that escape the current working directory. The upload path did not reuse the validate_safe_path helper introduced for the download fix.

Attack Vector

Exploitation occurs over the network through the MCP transport. The attacker does not need authentication to the MCP server in the vulnerable configuration and does not require user interaction. The scope is changed because files read by the MCP process on the host are exfiltrated into a separate Confluence tenant.

python
# Patched handler in src/mcp_atlassian/confluence/attachments.py
# Confine the upload source to the workspace before it is read: reject
# traversal/absolute paths that escape CWD (arbitrary file read /
# exfiltration via a caller-supplied file_path).
file_path = str(validate_safe_path(file_path))

# Check if file exists
if not os.path.exists(file_path):
    ...

Source: GitHub Commit b041733

Detection Methods for CVE-2026-77262

Indicators of Compromise

  • Confluence attachments containing sensitive host artifacts such as passwd, shadow, .env, id_rsa, or cloud credential files.
  • MCP Atlassian server logs recording confluence_upload_attachment calls with absolute file_path values or .. traversal segments.
  • Confluence audit events showing bulk attachment uploads from the MCP service account outside expected content workflows.

Detection Strategies

  • Inspect MCP request payloads for file_path arguments that begin with /, \, a drive letter, or contain ../ sequences.
  • Correlate MCP tool invocations with Confluence attachment metadata to flag uploads whose source path lies outside a defined workspace root.
  • Alert on attachments whose file names or MIME types match sensitive system files rather than expected document formats.

Monitoring Recommendations

  • Enable verbose logging on the MCP Atlassian server and forward events to a central log store for retention and analysis.
  • Monitor the Confluence REST API attachment endpoints for anomalous upload volume or size originating from the MCP integration account.
  • Track the deployed version of mcp-atlassian across hosts and alert on any instance below 0.22.0.

How to Mitigate CVE-2026-77262

Immediate Actions Required

  • Upgrade MCP Atlassian to version 0.22.0 or later on every host running the server.
  • Rotate any credentials, API tokens, or private keys stored on hosts where the vulnerable version was reachable.
  • Review Confluence attachment history for uploads created by the MCP service account and remove any files sourced outside the intended workspace.

Patch Information

The fix ships in MCP Atlassian v0.22.0 and is tracked in Pull Request #1448. The change routes file_path through validate_safe_path, the same helper introduced for CVE-2026-27825, so upload sources are confined to the working directory. Full details are in GHSA-p6hp-93wp-fh6p.

Workarounds

  • Disable the confluence_upload_attachment tool in MCP server configuration until the upgrade is applied.
  • Run the MCP Atlassian process as a low-privilege user with access limited to a dedicated workspace directory.
  • Place the MCP server behind an authenticating reverse proxy and restrict callers to trusted clients.
bash
# Upgrade MCP Atlassian to the patched release
pip install --upgrade "mcp-atlassian>=0.22.0"

# Verify installed version
python -c "import importlib.metadata; print(importlib.metadata.version('mcp-atlassian'))"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.