PatchSiren cyber security CVE debrief
CVE-2026-77246 sooperset CVE debrief
A vulnerability in MCP Atlassian, a Model Context Protocol (MCP) server for Atlassian products, allows an attacker to send a server-local file to a selected attachment endpoint without proper authorization. This issue is fixed in version 0.22.0. The vulnerability arises from an HTTP transport deployment with READ_ONLY_MODE=false that accepts a request without an Authorization identity and permits attacker-controlled Atlassian service headers. This can lead to unauthorized file transfers, potentially impacting the security and integrity of affected systems.
- Vendor
- sooperset
- Product
- mcp-atlassian
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for MCP Atlassian deployments should assess their exposure and prioritize upgrading to version 0.22.0. Those responsible for MCP Atlassian deployments should verify their configurations, assess their exposure, and prioritize upgrading to version 0.22.0. The impact of this vulnerability requires verification from official sources, and defenders should care about CVE-2026-77246 because it allows unauthorized file transfer in MCP Atlass
Why it matters
Defenders should care about CVE-2026-77246 because it allows unauthorized file transfer in MCP Atlassian deployments. Those responsible for MCP Atlassian deployments should assess their exposure, verify their configurations, and prioritize upgrading to version 0.22.0. The impact of this vulnerability requires verification from official sources.
- Potential unauthorized file transfer
- Possible exploitation of vulnerable deployments
- Verification of deployment configurations required
- Upgrade to version 0.22.0 recommended
Technical summary
MCP Atlassian, a Model Context Protocol (MCP) server for Atlassian products, is vulnerable to an authorization bypass. An attacker can send a server-local file to a selected attachment endpoint without proper authorization. The issue is fixed in version 0.22.0. This vulnerability arises from the server's acceptance of requests without proper authorization and its handling of attacker-controlled Atlassian service headers. Affected deployments should prioritize upgrading to version 0.22.0 and verify their configurations.
Defensive priority
Defenders should prioritize upgrading to version 0.22.0 and verify the configuration of their MCP Atlassian deployment.
Recommended defensive actions
- Upgrade to version 0.22.0
- Verify the configuration of your MCP Atlassian deployment
- Monitor for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability allows an attacker to send a server-local file to a selected attachment endpoint without proper authorization. The issue is fixed in version 0.22.0. Evidence of this vulnerability includes the ability to invoke confluence_upload_attachment or the Jira attachment variant with a server-local file_path, causing the MCP process to send the file to the selected attachment endpoint. Defenders should verify their configurations, assess their exposure, and prioritize upgrading to version 0.22.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77246 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77246
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77246 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77246
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/pull/1448
[email protected] - Issue Tracking, Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-wv8v-v4c5-v75j
[email protected] - Exploit, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.