{"id":"CVE-2026-77254","title":"MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)","summary":"MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, requests to the HTTP MCP endpoint without a per-user identity are allowed to reach tool handlers, which then use global…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-306"],"vendor":"sooperset","product":"mcp-atlassian","affected":["mcp-atlassian < 0.22.0"],"published":"2026-09-22","updated":"2026-09-23","sourceUpdated":"2026-09-23T18:28:25.093","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77254","references":[{"url":"https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/pull/1448","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-vc8m-84rp-53hx","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-vc8m-84rp-53hx","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00609,"epssPercentile":0.4786,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-22T19:04:19.773536Z"},"ingestedAt":"2026-09-22T19:09:10.013Z","slug":"CVE-2026-77254","body":"## Overview\n\nMCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, requests to the HTTP MCP endpoint without a per-user identity are allowed to reach tool handlers, which then use globally configured Jira or Confluence credentials. A network caller can perform operations with the operator account's permissions unless the deployment has an independent authentication boundary. The advisory traces the vulnerable input and processing flow through streamable-http, UserTokenMiddleware, _get_fetcher, and global credentials, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":62,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}