Model Context Protocol Server Vulnerability in Atlassian Confluence and Jira
CVE-2026-77243

8.8HIGH

Key Information:

Vendor

Sooperset

Vendor
CVE Published:
22 September 2026

What is CVE-2026-77243?

The MCP Atlassian server, used with Confluence and Jira, has a vulnerability that allows unauthorized access to certain tools. Specifically, the ENABLED_TOOLS and TOOLSETS configurations fail to revalidate privileges during tool requests. This could permit clients to invoke otherwise restricted tools for read, write, or delete operations, bypassing the safeguards intended to uphold least-privilege principles. The issue is addressed in version 0.22.0, highlighting the importance of robust access control mechanisms.

Affected Version(s)

mcp-atlassian < 0.22.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.