CVE-2026-77262 is a path traversal vulnerability in MCP Atlassian versions prior to 0.22.0. The Confluence attachment-upload functionality accepts an attacker-controlled file_path and passes it to file handling without applying path validation or the workspace restriction used by the download functionality. An attacker can use traversal to select files outside the intended workspace that are readable by the MCP Atlassian server process, then cause those files to be uploaded as Confluence attachments.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This four-file Python/Bash proof-of-concept repository demonstrates CVE-2026-77262, a CWE-22 arbitrary-file-read flaw in sooperset/mcp-atlassian before 0.22.0. The documented vulnerable behavior is that confluence_upload_attachment opens its attacker-controlled file_path directly and uploads the content to the configured Confluence endpoint, without the safe-path validation applied to the corresponding download path. mcp_client.py launches an mcp-atlassian process over stdio, limits enabled tools to confluence_upload_attachment, and invokes that tool with an arbitrary CLI-provided path. mock_confluence.py is a loopback HTTP stub that accepts the simulated Confluence requests and saves their raw multipart bodies. poc_run1.sh orchestrates both components against /etc/passwd and verifies that the root:x:0:0 marker appears in the capture. The exploit provides file disclosure and outbound exfiltration rather than code execution; remote impact depends on exposure of the MCP service and an attacker-controllable or attacker-observable configured Confluence destination.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical path-traversal/arbitrary-file-read vulnerability in sooperset/mcp-atlassian's confluence_upload_attachment MCP tool. Attacker-controlled file paths reach open(..., "rb") without validation, allowing exfiltration of files readable by the server process. The default streamable-http deployment binds to 0.0.0.0 without built-in authentication, enabling remote unauthenticated exploitation when network reachable.
A path-traversal/arbitrary-file-upload vulnerability in MCP Atlassian's confluence_upload_attachment function. Before version 0.22.0, an attacker-controlled file_path could reference files outside the workspace, allowing server-readable files to be uploaded to Confluence.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.