CVE-2026-27825Disclosure(mcp-atlassian / mcp_atlassian)

HIGHCVSS 8.0 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch mcp-atlassian mcp_atlassian systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_download_attachment` MCP tool accepts a `download_path` parameter that is written to without any directory boundary enforcement. An attacker who can call this tool and supply or access a Confluence attachment with malicious content can write arbitrary content to any path the server process has write access to. Because the attacker controls both the write destination and the written content (via an uploaded Confluence attachment), this constitutes for arbitrary code execution (for example, writing a valid cron entry to `/etc/cron.d/` achieves code execution within one scheduler cycle with no server restart required). Version 0.17.0 fixes the issue.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-73

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp_atlassian

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 24 mentions across 12 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 13 signals
  • Disclosure: 10 classified signals
  • General: 6 classified signals
  • Peaked 5d ago at 5 mentions (2026-03-10); latest day: 1
  • 24 total mentions across 12 days

Affected systems

Products
mcp_atlassian

Deep dive

Activity timeline24 mentions / 12d
01345Mentions · 2026-02-27: 2Mentions · 2026-03-02: 1Mentions · 2026-03-03: 2Mentions · 2026-03-04: 2Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-10: 5Mentions · 2026-03-11: 3Mentions · 2026-03-18: 2Mentions · 2026-04-20: 3Mentions · 2026-04-22: 1Mentions · 2026-09-16: 1PoC Mentioned / Linked · 2026-09-16: 1Exploit Tool / Code · 2026-04-20: 1Exploit Tool / Code · 2026-09-16: 1Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-04-22: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-02-27: 2Technical Details · 2026-03-02: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-10: 3Technical Details · 2026-03-11: 1Technical Details · 2026-04-20: 3Technical Details · 2026-04-22: 1Technical Details · 2026-09-16: 102-2703-0203-0303-0403-0503-0603-1003-1103-1804-2004-2209-16
Signal classification5 categories
Disclosure
1041.7%
General
625.0%
Patch
625.0%
Active Exploitation
14.2%
Exploit
14.2%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-02-272
Disclosure2
2026-03-021
Disclosure1
2026-03-032
Disclosure2
2026-03-042
General1Patch1
2026-03-051
General1
2026-03-061
Patch1
2026-03-105
Disclosure2General2Patch1
2026-03-113
General2Patch1
2026-03-182
Disclosure1Patch1
2026-04-203
Active Exploitation1Disclosure2
2026-04-221
Patch1
2026-09-161
Exploit1
Full discourse20 posts
  • Yotam Perkal@pyotam2
    Disclosure

    We disclosed a critical unauthenticated RCE chain in mcp-atlassian (4M+ downloads). CVE-2026-27826 - SSRF via Atlassian URL headers CVE-2026-27825 - Arbitrary file write → RCE Fixed in 0.17.0. Full breakdown 👇 https://blog.pluto.security/p/mcpwnfluence-cve-2026-27825-critical

    Post summary

    The text announces the disclosure of two critical vulnerabilities in mcp-atlassian, detailing their exploitation mechanisms and providing a patch version.

    1300130616.5K
    587 followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-27825: Critical Unauthenticated RCE and SSRF in mcp-atlassian https://arcticwolf.com/resources/blog/cve-2026-27825/

    Post summary

    The post announces a critical unauthenticated RCE and SSRF vulnerability in mcp‑atlassian (CVE‑2026‑27825) with no mention of PoC, exploit code, or active exploitation.

    1401081.8K
    152.0K followersView on X
  • Andre Gironda@AndreGironda
    Disclosure

    MCPwnfluence: CVE-2026-27825 Critical Unauthenticated Remote Code Execution Vulnerability in mcp-attlasian -- https://blog.pluto.security/p/mcpwnfluence-cve-2026-27825-critical

    Post summary

    A critical unauthenticated remote code execution vulnerability (CVE-2026-27825) in mcp‑attlasian has been disclosed.

    03070578
    3.6K followersView on X
  • Arctic Wolf@AWNetworks
    Patch

    On February 24, 2026, sooperset, the mcp-atlassian project maintainer, released fixes for a critical vulnerability in mcp-atlassian, tracked as CVE-2026-27825. Learn more in our latest security bulletin: https://ow.ly/oPaU50Yof5E

    Post summary

    The text announces the release of fixes for CVE-2026-27825 by the mcp-atlassian maintainer, with a link to a security bulletin.

    11030270
    4.4K followersView on X
  • Bob Skelley@ChannelSkell
    Patch

    On February 24, 2026, sooperset, the mcp-atlassian project maintainer, released fixes for a critical vulnerability in mcp-atlassian, tracked as CVE-2026-27825. Learn more in our latest security bulletin: https://livesocial.seismic.com/tc598p

    Post summary

    The maintainer released fixes for CVE-2026-27825 and provided a link to a security bulletin containing the patch information.

    1101066
    681 followersView on X
  • ナタリー 🌙@Absolcasso
    Patch

    @luckyPipewrench @zaimiri Exactly. CVE-2026-3484 in nmap-mcp-server and CVE-2026-27825 in mcp-atlassian were patched, but the architecture that lets injected payloads ride MCP responses is still there. One CVE at a time is the wrong unit of analysis.

    Post summary

    Both CVE-2026-3484 and CVE-2026-27825 have been patched, though the underlying vulnerable architecture still exists.

    1002045
    68 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 CVE-2026-27825 Arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment · Advisory · sooperset/mcp-atlassian · GitHub https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-xjgw-4wvw-rgm4

    Post summary

    The advisory announces CVE-2026-27825, detailing an arbitrary file write that can lead to code execution via an unconstrained download_path in confluence_download_attachment, and provides a GitHub link for further information.

    00021429
    6.7K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27825: CRITICAL] Atlassian's MCP server for Confluence and Jira had a security flaw allowing attackers to write arbitrary content pre-0.17.0 update. Ensure your systems are updated to stay secure.#cve,CVE-2026-27825,#cybersecurity https://cvefind.com/CVE-2026-27825

    Post summary

    Atlassian's MCP server for Confluence and Jira had a critical flaw before version 0.17.0 that permits attackers to write arbitrary content; users are urged to update to mitigate the risk.

    0002069
    601 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-27825 - Critical MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_download_attachment` MCP tool accepts a `down... https://www.thehackerwire.com/vulnerability/CVE-2026-27825/ https://t.co/h6jyAIWGgV

    Post summary

    A critical vulnerability (CVE-2026-27825) affecting MCP Atlas server’s confluence_download_attachment tool in versions before 0.17.0 has been disclosed.

    0002059
    133 followersView on X
  • シンギュラリティ研究所🐒@guava_asi
    Disclosure

    guard-scanner v5.0.5 released 🛡️ 147 patterns / 23 categories / 136 tests PASS 0.016ms/scan / zero deps New: CVE-2026-25905, CVE-2026-27825, VDB Injection (Cat 23) npm: http://npmjs.com/package/guard-scanner GitHub: http://github.com/koatora20/guard-scanner #AIAgentSecurity #OpenClaw

    Post summary

    Guard‑scanner v5.0.5 is released, adding detection for CVE‑2026‑25905, CVE‑2026‑27825, and VDB Injection.

    00101233
    15 followersView on X
  • Christopher Elliott@Chris_L_Elliott
    Exploit

    Pluto + KELA: working MCPwnfluence exploit writeups are in the wild now. Same chain on unauth HTTP mcp-atlassian <0.17.0: CVE-2026-27826 spoof X-Atlassian-Confluence-Url + CVE-2026-27825 confluence_download_attachment with attacker download_path (e.g. /etc/cron.d/) = RCE. Floor is still 0.17.0 (Feb). If that connector is network-exposed without auth, the model isn't your weakest link — the MCP is. https://pluto.security/blog/mcp-servers-exploited-enterprise-risk/

    Post summary

    The text reports publicly available MCPwnfluence exploit writeups targeting unauthenticated MCP Atlassian connectors via CVE-2026-27826 and CVE-2026-27825, achieving RCE, with a reference to a detailed blog post but no named patch or active-exploitation claim.

    10000100
    59 followersView on X
  • Hermetic@HermeticSys
    Patch

    MCP security this month: Week 1: CVE-2026-33032 — nginx-ui MCP endpoint, CVSS 9.8, zero auth Week 1: CVE-2026-27825/26 — Atlassian MCP server, unauthenticated RCE Week 2: Vercel breached via AI tool OAuth → credential exposure Week 2: OX Security finds RCE in Anthropic's MCP SDK itself — 150M+ downloads Anthropic says the SDK behavior is "expected." That means the security layer has to come from outside the protocol. The recommended mitigations from every researcher: sandbox MCP servers, scan responses, pin tool definitions, audit tool calls. That's literally what @HermeticSys's MCP Proxy does. We built HC-17 (9 security clauses) because we saw this coming. Not a gateway. Not a cloud service. A local proxy between your agent and any MCP server. http://hermeticsys.com/blog/mcp-security-broken/

    Post summary

    The text lists multiple high‑severity MCP server and SDK vulnerabilities, notes active exploitation (e.g., Vercel breach), and focuses on recommended mitigations such as sandboxing and a local proxy to address the risks.

    00010161
    10 followersView on X
  • CERT Azerbaijan@CERTAzerbaijan
    Disclosure

    “Cisco IOS XE” əməliyyat sistemində boşluq (CVE-2026-27825) aşkarlanıb. #ETX #MilliCERT #cybersecurity #kibertəhlükəsizlik #xəbərdarlıq https://t.co/lNdDpoXv9z

    Post summary

    A vulnerability CVE-2026-27825 has been discovered in Cisco IOS XE.

    0001078
    134 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 CVE-2026-27825: mcp-atlassian vulnerability allows arbitrary file writes, which can lead to code execution. Update to v0.17.0 ASAP; use temporary workarounds to limit exposure until patched. 🔍 https://vulert.com/vuln-db/CVE-2026-27825 #CyberSecurity #AppSec #Vulert https://t.co/zQHdusu3I0

    Post summary

    The tweet announces CVE-2026-27825, highlights its severity by describing arbitrary file writes leading to code execution, and urges users to update to v0.17.0 immediately, offering temporary workarounds until a patch is applied.

    0001045
    124 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27825 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_download_attachment` MCP… https://www.cve.org/CVERecord?id=CVE-2026-27825

    Post summary

    The text lists CVE-2026-27825 with a brief link to the CVE record but provides no further technical, exploit, or mitigation details.

    10000246
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-27825: MCP Atlassian has an arbitrary f... Path traversal meets cron injection - drop a malicious Confluence attachment, control download_path, own the box in one... https://zerodaysignal.com/vulnerability/CVE-2026-27825 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑27825, describing a path traversal and cron injection flaw in Atlassian Confluence that lets an attacker upload malicious attachments and gain full system control.

    0001072
    142 followersView on X
  • ナタリー 🌙@Absolcasso
    General

    MCPサーバーのCVEが15ヶ月で30件超。36%が認証なしで稼働中という調査結果も出てる。今週だけでもmcp-atlassian(CVE-2026-27825)とContext7 MCP Serverに重大な脆弱性が報告された。便利さに飛びつく前に、接続先のサーバーが安全かどうか確認する習慣をつけないと本当にまずい。

    Post summary

    The post highlights that many MCP servers have CVEs, with a sizable portion running unauthenticated, and notes recent serious vulnerabilities, urging users to verify their server security.

    0001086
    68 followersView on X
  • Hermetic@HermeticSys
    Disclosure

    .@AnthropicAI MCP is spreading fast but the ecosystem security story is rough: - CVE-2026-33032: nginx-ui MCP endpoint, zero auth, CVSS 9.8 - CVE-2026-27825/26: Atlassian MCP server, unauthenticated RCE - Even Anthropic's own Git MCP server had 3 CVEs in January The protocol needs an auth standard, not just a capability standard. Right now every MCP server reinvents authentication differently, and most get it wrong. We built @HermeticSys as an MCP proxy that scans every tool response for credential leaks and pins tool definitions with SHA-256 hashes. MCP-native, but with a security layer the protocol doesn't provide.

    Post summary

    The post announces several newly disclosed CVEs in MCP servers, detailing authentication weaknesses and severity scores, but offers no proof of exploitation, PoC, or patches.

    0000050
    10 followersView on X
  • Hermetic@HermeticSys
    Disclosure

    .@YotamPerkal at @PlutoSecurity found both MCPwn (CVE-2026-33032) and MCPwnfluence (CVE-2026-27825/27826) in the same research program. His finding: "When you bolt MCP onto an existing application, the MCP endpoints inherit the application's full capabilities but not necessarily its security controls." 43% of public MCP servers vulnerable to command execution. 36.7% vulnerable to SSRF. 53% use static credentials. Average security score: 34/100. The MCP ecosystem has a systemic auth problem. The protocol was designed for capability, not containment. #MCP #infosec

    Post summary

    Researchers have disclosed multiple vulnerabilities in the MCP ecosystem, providing statistics on command execution, SSRF, and credential issues.

    0000034
    10 followersView on X
  • Hermetic@HermeticSys
    Active Exploitation

    This week in "MCP endpoints that forgot about auth": Monday: CVE-2026-33032 — nginx-ui's MCP endpoint had no auth. CVSS 9.8. Full server takeover in two HTTP requests. Actively exploited. Wednesday: CVE-2026-27825 + CVE-2026-27826 — Atlassian MCP server. Unauthenticated RCE from the LAN. Saturday: @vercel breached via @ContextAI OAuth chain. Env vars not marked "sensitive" exposed. The pattern: MCP gives agents power. Nobody is verifying who the agent is or what credentials it can access. 43% of public MCP servers are vulnerable to command execution. This isn't slowing down. #infosec #MCP

    Post summary

    Multiple MCP endpoints, such as nginx‑ui and Atlassian, are exposed to unauthenticated RCEs; the listed CVEs are actively exploited with no patches or mitigations discussed.

    0000046
    10 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmcp-atlassianmcp_atlassian---

Explore more