Model Context Protocol Server Vulnerability in Atlassian Products
CVE-2026-77250

6.1MEDIUM

Key Information:

Vendor

Sooperset

Vendor
CVE Published:
22 September 2026

What is CVE-2026-77250?

The Model Context Protocol (MCP) server for Atlassian products, including Confluence and Jira, contains a vulnerability in the OAuthConfig component. This issue arises when a plaintext fallback file is created that stores sensitive access and refresh tokens in the user's .mcp-atlassian directory. If the system is configured with a permissive umask, these tokens might be exposed to other local users and processes, allowing them to access and misuse the tokens linked to an Atlassian account. The issue has been addressed in version 0.22.0, ensuring that token management adheres to better security practices to prevent unauthorized access.

Affected Version(s)

mcp-atlassian < 0.22.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.