Model Context Protocol Vulnerability in Atlassian Confluence and Jira
CVE-2026-77261

7.1HIGH

Key Information:

Vendor

Sooperset

Vendor
CVE Published:
22 September 2026

What is CVE-2026-77261?

The MCP Atlassian server for Atlassian's Confluence and Jira products has a session management flaw due to the omission of the _make_ssrf_safe_hook function in sessions established via basic-auth and oauth_pat. This could allow an attacker to redirect sessions to internal addresses without proper validation, resulting in potential unauthorized access to internal resources. It is crucial for users to upgrade to version 0.22.0 or later to mitigate this vulnerability.

Affected Version(s)

mcp-atlassian < 0.22.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.