PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77253 sooperset CVE debrief

A vulnerability in MCP Atlassian, a Model Context Protocol (MCP) server for Atlassian products, allows disclosure of configuration, credentials, and other sensitive files readable by the MCP process. The issue, fixed in version 0.22.0, arises from the acceptance of arbitrary local filesystem paths in Jira and Confluence attachment upload tools. This vulnerability can lead to potential disclosure of sensitive information, including configuration and credentials, and may allow an attacker to cross the client-to-server filesystem boundary. Defenders should assess exposure and prioritize remediation to prevent potential security breaches.

Vendor
sooperset
Product
mcp-atlassian
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-22
Original CVE updated
2026-09-28
Advisory published
2026-09-22
Advisory updated
2026-09-28

Who should care

Defenders of HTTP or multi-user deployments using MCP Atlassian should assess exposure and prioritize remediation to prevent potential security breaches. This includes reviewing filesystem access controls, upgrading to version 0.22.0, and monitoring for suspicious attachment uploads. Security teams and vulnerability management teams should also be aware of the potential risks and take necessary actions to protect their systems.

Why it matters

Defenders should prioritize verifying exposure in HTTP or multi-user deployments, reviewing filesystem access controls, and upgrading to version 0.22.0 to prevent potential disclosure of sensitive information.

  • Potential disclosure of configuration and credentials
  • Possible exposure of mounted secrets or other sensitive files
  • Verification of filesystem access controls is necessary
  • Upgrade to version 0.22.0 to remediate the vulnerability

Technical summary

MCP Atlassian, a Model Context Protocol (MCP) server for Atlassian products, is vulnerable to disclosure of configuration, credentials, and other sensitive files readable by the MCP process. The issue arises from the acceptance of arbitrary local filesystem paths in Jira and Confluence attachment upload tools, allowing a caller to cross the client-to-server filesystem boundary. This vulnerability can lead to potential disclosure of sensitive information, including configuration and credentials. The issue is fixed in version 0.22.0.

Defensive priority

Defenders should prioritize verifying exposure in HTTP or multi-user deployments, reviewing filesystem access controls, and upgrading to version 0.22.0.

Recommended defensive actions

  • Verify exposure in HTTP or multi-user deployments
  • Review filesystem access controls
  • Upgrade to version 0.22.0
  • Monitor for suspicious attachment uploads
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The advisory provides details on the vulnerable input and processing flow through jira_upload_attachment, confluence_upload_attachment, file_path, and server-local filesystem. It also notes that the issue is fixed in version 0.22.0 and that defenders should verify exposure in HTTP or multi-user deployments, review filesystem access controls, and upgrade to the latest version to prevent potential disclosure of sensitive information. The advisory includes information on the affected entry points, controls, and code paths.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77253 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77253

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77253 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77253

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.