OAuth Token Directory Vulnerability in MCP Atlassian for Confluence and Jira
CVE-2026-77268
5.5MEDIUM
What is CVE-2026-77268?
The MCP Atlassian server used for Confluence and Jira prior to version 0.22.0 suffers from a vulnerability where the OAuth fallback token directory and associated JSON files lack appropriate owner-only permissions. This misconfiguration allows local users or processes with group or world access to read sensitive access and refresh tokens. If exploited, these tokens can be reused to gain unauthorized access to the associated Atlassian sessions. The risk has been addressed in version 0.22.0, which implements necessary file permission restrictions to safeguard token information.
Affected Version(s)
mcp-atlassian < 0.22.0
