Vulnerability  ·  2026-09-28

mcp-atlassian 'MCPwnfluence' exploit chain weaponized: working RCE exploit circulating on a cybercrime forum

VulnerabilityHigh impactGlobalCVE-2026-27826
Per pluto.security (with KELA), a working MCPwnfluence exploit chain for mcp-atlassian surfaced on the XSS.PRO cybercrime forum 20 days after the patched version released and six days after the CVEs hit NVD. The chain combines an unauthenticated open HTTP MCP transport with content redirection and an arbitrary filesystem write, demonstrated to write a malicious cron file for RCE. Same MCP attack pattern (auth gaps) was seen weaponized against nginx-ui and Flowise, which VulnCheck recorded as actively exploited.
This documents the first real-world weaponization of a Jira/Confluence MCP integration into host RCE, confirming attackers are actively targeting exposed MCP servers as an enterprise entry path. The chain runs entirely through the agent/tool boundary — the attacker never touches the model — and the working forum PoC elevates it from advisory to active-threat signal for anyone operating unauthenticated MCP servers.
An unauthenticated attacker initializes an MCP session over HTTP, supplies a spoofed X-Atlassian-Confluence-Url header pointing at attacker-controlled infrastructure, then invokes the Confluence download/attachment tool to write attacker-controlled content to an unrestricted filesystem location (demonstrated to /etc/cron.d) — turning an AI tool call into host RCE when the scheduled job executes.
mcp-atlassian MCP server before 0.17.0 (Jira/Confluence agent integrations); chained CVEs CVE-2026-27826 (request redirection) and CVE-2026-27825 (arbitrary write)
Upgrade to mcp-atlassian 0.17.0 or later; inventory and isolate MCP servers; enforce authentication and restrict filesystem/network permissions. Analysis: https://pluto.security/blog/mcp-servers-exploited-enterprise-risk/
Pluto Security (primary)NVD CVE-2026-27826
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →