Unauthorized Access in MCP Atlassian Server for Confluence and Jira
CVE-2026-77244
10CRITICAL
What is CVE-2026-77244?
The MCP Atlassian server for Confluence and Jira is susceptible to unauthorized access due to a flaw in its HTTP transport mechanism. Versions prior to 0.22.0 do not properly verify user identities, allowing a network client reaching the MCP endpoint to execute commands as the operator. This could enable unauthorized read and write operations, taking advantage of the operator's configured credentials. A detailed advisory traces the risk through several entry points and control mechanisms, outlining the path through systems like UserTokenMiddleware and AtlassianOpaqueTokenVerifier. The issue has been rectified in version 0.22.0, reinforcing the need for timely updates to mitigate potential exploitation.
Affected Version(s)
mcp-atlassian < 0.22.0
