← Back to search

CVE-2026-77262

8.6 HIGHpublic exploit available

Published 2026-09-22 · Updated 2026-09-28

AI risk analysis

Summary
This flaw allows an attacker to upload arbitrary files outside the workspace by manipulating the file_path parameter in confluence_upload_attachment, potentially leading to unauthorized access to server-readable files.
Exploitability
Exploitation is moderately hard as it requires control over the file_path parameter, but preconditions such as access to the Confluence server are necessary.
Blast radius
If exploited, the impact is limited to the Confluence server, where unauthorized files could be uploaded and accessed, potentially leading to data exposure or further attacks.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to MCP Atlassian version 0.22.0 or later.
uploadfileweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment accepts an attacker-controlled file_path and does not apply the path restriction added for the earlier download vulnerability. A caller can traverse outside the workspace and upload arbitrary server-readable files to Confluence. The advisory traces the vulnerable input and processing flow through confluence_upload_attachment, file_path, and CVE-2026-27825, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Weaknesses

CWE-22

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.