CVE-2026-27826Disclosure(sooperset / mcp_atlassian)

HIGHCVSS 8.2 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch sooperset mcp_atlassian systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, an unauthenticated attacker who can reach the mcp-atlassian HTTP endpoint can force the server process to make outbound HTTP requests to an arbitrary attacker-controlled URL by supplying two custom HTTP headers without an `Authorization` header. No authentication is required. The vulnerability exists in the HTTP middleware and dependency injection layer — not in any MCP tool handler - making it invisible to tool-level code analysis. In cloud deployments, this could enable theft of IAM role credentials via the instance metadata endpoint (`169[.]254[.]169[.]254`). In any HTTP deployment it enables internal network reconnaissance and injection of attacker-controlled content into LLM tool results. Version 0.17.0 fixes the issue.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp_atlassian

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 10 mentions across 9 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 2 mentions (2026-03-11); latest day: 1
  • 10 total mentions across 9 days

Affected systems

Vendors
Products
mcp_atlassian

Deep dive

Activity timeline10 mentions / 9d
01122Mentions · 2026-02-27: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 2Mentions · 2026-04-20: 1Mentions · 2026-05-08: 1Mentions · 2026-06-17: 1Mentions · 2026-07-10: 1Mentions · 2026-09-16: 1Mentions · 2026-09-17: 1PoC Mentioned / Linked · 2026-02-27: 1PoC Mentioned / Linked · 2026-06-17: 1PoC Mentioned / Linked · 2026-09-16: 1Exploit Tool / Code · 2026-04-20: 1Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-05-08: 1Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 1Technical Details · 2026-04-20: 1Technical Details · 2026-05-08: 1Technical Details · 2026-06-17: 1Technical Details · 2026-07-10: 1Technical Details · 2026-09-16: 102-2703-1003-1104-2005-0806-1707-1009-1609-17
Signal classification4 categories
Disclosure
550.0%
General
220.0%
Active Exploitation
220.0%
PoC
110.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-271
Disclosure1
2026-03-101
Disclosure1
2026-03-112
Disclosure1General1
2026-04-201
Active Exploitation1
2026-05-081
Active Exploitation1
2026-06-171
Disclosure1
2026-07-101
Disclosure1
2026-09-161
PoC1
2026-09-171
General1
Full discourse10 posts
  • Yotam Perkal@pyotam2
    Disclosure

    We disclosed a critical unauthenticated RCE chain in mcp-atlassian (4M+ downloads). CVE-2026-27826 - SSRF via Atlassian URL headers CVE-2026-27825 - Arbitrary file write → RCE Fixed in 0.17.0. Full breakdown 👇 https://blog.pluto.security/p/mcpwnfluence-cve-2026-27825-critical

    Post summary

    A critical unauthenticated RCE chain in mcp‑atlassian (CVE‑2026‑27825/27826) was disclosed with technical details and a patch (v0.17.0) referenced in a blog post.

    1300130616.5K
    587 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-27826 - High MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, an unauthenticated attacker who can reach the mcp-atlassian HTTP ... https://www.thehackerwire.com/vulnerability/CVE-2026-27826/ https://t.co/Xg27nAwxf1

    Post summary

    The tweet announces a high‑severity vulnerability (CVE‑2026‑27826) affecting MCP Atlassian servers before v0.17.0, noting that unauthenticated attackers can reach the HTTP endpoint, but provides no proof of exploitation or remediation information.

    0101061
    133 followersView on X
  • Christopher Elliott@Chris_L_Elliott
    General

    @catidegla Exactly—the CVE-2026-27826 side is the blind spot when scanners stop at tool manifests. The policy needs to inspect the resolved middleware request plus download_path, not just the declared tool schema.

    Post summary

    The text mentions CVE-2026-27826 in the context of scanner blind spots and policy improvements, but lacks specific indicators for other categories like exploitation or patching.

    1000034
    60 followersView on X
  • Christopher Elliott@Chris_L_Elliott
    PoC

    Pluto + KELA: working MCPwnfluence exploit writeups are in the wild now. Same chain on unauth HTTP mcp-atlassian <0.17.0: CVE-2026-27826 spoof X-Atlassian-Confluence-Url + CVE-2026-27825 confluence_download_attachment with attacker download_path (e.g. /etc/cron.d/) = RCE. Floor is still 0.17.0 (Feb). If that connector is network-exposed without auth, the model isn't your weakest link — the MCP is. https://pluto.security/blog/mcp-servers-exploited-enterprise-risk/

    Post summary

    The tweet reports that working exploit writeups for a two‑stage chain involving CVE‑2026‑27826 (URL spoofing) and CVE‑2026‑27825 (attachment download) are publicly available, detailing how unauthenticated mcp‑atlassian <0.17.0 can be driven to remote code execution. It warns that the vulnerable connector remains in production and emphasizes the risk posed by the exposed MCP component.

    10000100
    59 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-27826 - high 🚨 mcp-atlassian &lt; 0.17.0 - Server-Side Request Forgery &gt; MCP Atlassian &lt; 0.17.0 contains a server-side request forgery caused by improper vali... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-27826 @pdnuclei #NucleiTemplates #cve

    Post summary

    High‑severity SSRF vulnerability (CVE‑2026‑27826) disclosed for mcp‑atlassian versions below 0.17.0, with a link to potential PoC resources and no indication of active exploitation or mitigation information.

    00010126
    959 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 mcp-atlassian, SSRF via DNS Rebinding TOCTOU, #CVE-2026-27826 (High) -DC-Jul2026-857 https://dailycve.com/mcp-atlassian-ssrf-via-dns-rebinding-toctou-cve-2026-27826-high-dc-jul2026-857/

    Post summary

    The post announces a new high‑severity SSRF vulnerability (CVE‑2026‑27826) involving DNS rebinding, directing readers to a dailyCVE page for further details.

    0000058
    218 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited SSRF vulnerabilities in MCP servers to achieve remote code execution and lateral movement. CVE-2026-27826 allowed unauthenticated access via crafted HTTP headers, enabling internal network reconnaissance and privilege escalation. Runtime segmentation could help contain such post-compromise pivoting across internal systems. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/otto-support-ssrf-token-passthrough-with-mcp

    Post summary

    Trained attackers exploited CVE‑2026‑27826 via SSRF in MCP servers, enabling remote code execution, internal reconnaissance, and privilege escalation, demonstrating active exploitation in the wild.

    0000035
    1.9K followersView on X
  • Hermetic@HermeticSys
    Active Exploitation

    This week in "MCP endpoints that forgot about auth": Monday: CVE-2026-33032 — nginx-ui's MCP endpoint had no auth. CVSS 9.8. Full server takeover in two HTTP requests. Actively exploited. Wednesday: CVE-2026-27825 + CVE-2026-27826 — Atlassian MCP server. Unauthenticated RCE from the LAN. Saturday: @vercel breached via @ContextAI OAuth chain. Env vars not marked "sensitive" exposed. The pattern: MCP gives agents power. Nobody is verifying who the agent is or what credentials it can access. 43% of public MCP servers are vulnerable to command execution. This isn't slowing down. #infosec #MCP

    Post summary

    The tweet announces several actively exploited MCP endpoint vulnerabilities, including nginx‑ui and Atlassian servers, with no patches or workarounds mentioned.

    0000046
    10 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27826 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, an unauthenticated attacker who can reac… https://www.cve.org/CVERecord?id=CVE-2026-27826

    Post summary

    The message announces CVE‑2026‑27826, noting that MCP servers before version 0.17.0 are vulnerable to unauthenticated exploitation; no PoC, exploit, or patch details are provided.

    00000229
    56.7K followersView on X
  • ナタリー 🌙@natalie_avfieb
    General

    CoSAI mapped 40 threats across MCP. Add CVE-2026-27825, CVE-2026-27826, and CVE-2026-26118, and the pattern is clear: auth is not enough. I keep MCP guard in front of every new server because runtime inspection matters.

    Post summary

    The tweet notes three CVEs and stresses poor authentication but lacks technical details, PoC references, exploit code, patch info, or active exploitation evidence.

    0000019
    78 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsoopersetmcp_atlassian---

Explore more