CVE-2026-73498Patch

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassian/confluence/attachments.py through _upload_attachment_direct() without calling validate_safe_path. An authenticated MCP client can read any file accessible to the server process and exfiltrate it to Confluence as an attachment. If an AI agent can be induced to call the tool through untrusted content, the same flaw can disclose server environment variables such as CONFLUENCE_API_TOKEN and other credentials. This issue is fixed in version 0.22.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-13); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-13: 1Mentions · 2026-09-12: 1Patch / Workaround · 2026-08-13: 1Patch / Workaround · 2026-09-12: 1Technical Details · 2026-08-13: 1Technical Details · 2026-09-12: 108-1309-12
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-131
Patch1
2026-09-121
Disclosure1
Full discourse2 posts
  • Ryx@PadhiyarRushi
    Disclosure

    Atlassian MCP had a clean path-traversal (CVE-2026-73498). confluence_upload_attachment took a client-supplied file path and passed it straight to open() with no validation. Authenticated MCP client → arbitrary file read of anything the server process can reach (credentials and env vars called out in the advisory). Fixed in v0.22.0. Classic “tool parameter treated as trusted” failure mode. https://adversa.ai/blog/top-mcp-security-resources-september-2026/ #MCP #AppSec #Cybersecurity #AI #Claude #VulnerabilityResearch #Infosec

    Post summary

    The post reports a path‑traversal flaw (CVE‑2026‑73498) in Atlassian MCP that lets authenticated clients read arbitrary files and notes it has been patched in v0.22.0.

    10031401
    930 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - mcp-atlassian Arbitrary File Read via confluence_upload_attachment (CVE-2026-73498) In mcp-atlassian, confluence_upload_attachment passes client-controlled file_path straight into open() with no safe-path validation. An authenticated MCP client (or prompt-injected agent) can read arbitrary server files and exfiltrate them to Confluence as attachments, leaking env vars/credentials. 👉Affected: mcp-atlassian < 0.22.0 | Upgrade to 0.22.0

    Post summary

    The post announces a high‑severity arbitrary file read vulnerability (CVE-2026-73498) in mcp‑atlassian and recommends upgrading to version 0.22.0.

    00000118
    288 followersView on X

Explore more