Model Context Protocol Server Vulnerability in Atlassian Products
CVE-2026-77250
6.1MEDIUM
What is CVE-2026-77250?
The Model Context Protocol (MCP) server for Atlassian products, including Confluence and Jira, contains a vulnerability in the OAuthConfig component. This issue arises when a plaintext fallback file is created that stores sensitive access and refresh tokens in the user's .mcp-atlassian directory. If the system is configured with a permissive umask, these tokens might be exposed to other local users and processes, allowing them to access and misuse the tokens linked to an Atlassian account. The issue has been addressed in version 0.22.0, ensuring that token management adheres to better security practices to prevent unauthorized access.
Affected Version(s)
mcp-atlassian < 0.22.0
