Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

MCP Atlassian server flaws allow SSRF and arbitrary file write before v0.17.0

Two vulnerabilities (CVE-2026-27826 and CVE-2026-27825) in the MCP Atlassian Model Context Protocol server allowed unauthenticated attackers to force outbound requests to arbitrary URLs via HTTP middleware, and allowed the confluence_download_attachment tool to write attacker-controlled content to arbitrary paths, enabling code execution. Both are fixed in version 0.17.0.

Disclosed 10 March 2026 · Record updated 13 September 2026

Impact

Unauthenticated SSRF could enable theft of cloud IAM role credentials via the instance metadata endpoint, internal network reconnaissance and injection of attacker-controlled content into LLM tool results; the unbounded download_path parameter permitted arbitrary file write leading to code execution (e.g. writing a cron entry to /etc/cron.d/).

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-27826
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-27825