MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call (CVE-2026-77266) | HOL Guard CVE