Unauthorized Access in MCP Atlassian Server for Confluence and Jira
CVE-2026-77244

10CRITICAL

Key Information:

Vendor

Sooperset

Vendor
CVE Published:
22 September 2026

What is CVE-2026-77244?

The MCP Atlassian server for Confluence and Jira is susceptible to unauthorized access due to a flaw in its HTTP transport mechanism. Versions prior to 0.22.0 do not properly verify user identities, allowing a network client reaching the MCP endpoint to execute commands as the operator. This could enable unauthorized read and write operations, taking advantage of the operator's configured credentials. A detailed advisory traces the risk through several entry points and control mechanisms, outlining the path through systems like UserTokenMiddleware and AtlassianOpaqueTokenVerifier. The issue has been rectified in version 0.22.0, reinforcing the need for timely updates to mitigate potential exploitation.

Affected Version(s)

mcp-atlassian < 0.22.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.