MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials (CVE-2026-77259) | HOL Guard CVE