Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

MCP Atlassian arbitrary file read vulnerability

MCP Atlassian versions prior to 0.22.0 allow authenticated clients to read arbitrary files accessible to the server process and exfiltrate them through Confluence attachments. If exploited through AI agents, this could expose sensitive credentials like API tokens and environment variables.

Disclosed 12 August 2026 · Record updated 13 September 2026

Impact

Arbitrary file read and credential disclosure via confluence_upload_attachment function without path validation

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-73498