# CVE-2026-73496

## Summary

- **CVE ID:** CVE-2026-73496
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
- **CWE:** CWE-22, CWE-73
- **Published:** Sep 14, 2026
- **Last Modified:** Sep 16, 2026

## Description

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlassian/confluence/attachments.py upload_attachment, and the jira_update_issue attachments parameter reaches src/mcp_atlassian/jira/attachments.py upload_attachment, without confining either path to an approved server workspace. In a remote HTTP, SSE, or multi-user deployment, absolute or traversing paths are resolved on the MCP server and uploaded to Atlassian, allowing a client with write-tool access to disclose server files, environment-held Atlassian credentials, or another tenant's data. A local single-user stdio deployment does not cross this trust boundary because the server runs in the caller's environment. This issue is fixed in version 0.22.0.

## Affected Products

- sooperset — mcp-atlassian (< 0.22.0)

## References

- [CNA](https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-wm45-qh3g-v83f)
- [CNA](https://github.com/sooperset/mcp-atlassian/pull/1448)
- [CNA](https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460)
- [CNA](https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.33%
- **EPSS Percentile:** 25.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._