MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport (CVE-2026-77248) | HOL Guard CVE