mcp-atlassian < 0.17.0 - Server-Side Request Forgery
CVE-2026-27826
Verified
Description
MCP Atlassian < 0.17.0 contains a server-side request forgery caused by improper validation of custom HTTP headers in the HTTP middleware, letting unauthenticated attackers force outbound requests to arbitrary URLs, exploit requires access to the mcp-atlassian HTTP endpoint.
Severity
High
CVSS Score
8.2
Exploit Probability
1%
Affected Product
mcp-atlassian
Published Date
April 16, 2026
Template Author
eyangfeng88-arch
CVE-2026-27826.yaml
8.2Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
CVE ID:
cve-2026-27826
CWE ID:
cwe-918
Remediation Steps
Upgrade to version 0.17.0 or later.