OAuth Token Directory Vulnerability in MCP Atlassian for Confluence and Jira
CVE-2026-77268

5.5MEDIUM

Key Information:

Vendor

Sooperset

Vendor
CVE Published:
22 September 2026

What is CVE-2026-77268?

The MCP Atlassian server used for Confluence and Jira prior to version 0.22.0 suffers from a vulnerability where the OAuth fallback token directory and associated JSON files lack appropriate owner-only permissions. This misconfiguration allows local users or processes with group or world access to read sensitive access and refresh tokens. If exploited, these tokens can be reused to gain unauthorized access to the associated Atlassian sessions. The risk has been addressed in version 0.22.0, which implements necessary file permission restrictions to safeguard token information.

Affected Version(s)

mcp-atlassian < 0.22.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.