[CVE-2026-27826] Otto Support - SSRF and Token Passthrough with MCP
bishopfox.com | blog | CVE-2026-27826 | #ai-security | #cloud | #rce | #mcp | #ssrf | #token-passthrough | #cve-2026-27826 | #markitdown
Summary
SSRF and token passthrough in MCP servers: the mcp-atlassian SSRF-to-RCE chain (CVE-2026-27826), MarkItDown's SSRF, and an OpenClaw marketplace plugin flaw show why destination validation matters.
- Published
- Collected
Skip to content