PatchSiren cyber security CVE debrief
CVE-2026-77243 sooperset CVE debrief
A vulnerability in MCP Atlassian, a Model Context Protocol (MCP) server for Atlassian products, allows unauthorized tool invocation. This issue, fixed in version 0.22.0, enables a client with knowledge of a hidden tool name to bypass configured least-privilege restrictions and directly invoke excluded read, write, or delete tools. The vulnerability arises from ENABLED_TOOLS and TOOLSETS being applied when tools are listed but not rechecked when a tools/call request is dispatched. This issue requires verification of inventory, assessment of exposure, and application of the patch to version 0.22.0. Security teams and administrators should monitor for unusual activity and implement
- Vendor
- sooperset
- Product
- mcp-atlassian
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-09-29
Who should care
Defenders responsible for MCP Atlassian instances, particularly those using Confluence and Jira, should assess exposure to vulnerable versions and apply the patch to version 0.22.0. Security teams and administrators should verify their inventory and monitor for unusual activity.
Why it matters
Defenders should care about CVE-2026-77243 because it allows unauthorized tool invocation in MCP Atlassian instances, potentially bypassing least-privilege restrictions. This requires verification of inventory, assessment of exposure, and application of the patch to version 0.22.0. Security teams and administrators should monitor for unusual activity and implement compensating controls as needed.
- Potential unauthorized tool invocation
- Bypass of configured least-privilege restrictions
- Possible read, write, or delete operations on excluded tools
- Verification of inventory and patch application required
Technical summary
The vulnerability in MCP Atlassian allows a client to bypass configured least-privilege restrictions and directly invoke excluded read, write, or delete tools if the client knows a hidden tool name. This issue is due to ENABLED_TOOLS and TOOLSETS being applied when tools are listed but not rechecked when a tools/call request is dispatched. The vulnerability is fixed in version 0.22.0. A client that knows a hidden tool name can directly invoke excluded tools despite the operator's configured least-privilege restrictions. The advisory traces the vulnerable input and processing flow through ENABLED_TOOLS, TOOLSETS, tools/list, tools/call, and _call_tool_mcp, which identify the affected entry points, controls, and
Defensive priority
Defenders should prioritize verifying their inventory of MCP Atlassian instances, assessing exposure to vulnerable versions, and applying the patch to version 0.22.0. Monitoring for unusual tool invocation patterns and implementing compensating controls may also be necessary.
Recommended defensive actions
- Verify inventory of MCP Atlassian instances and assess exposure to vulnerable versions
- Apply patch to version 0.22.0
- Monitor for unusual tool invocation patterns
- Implement compensating controls
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The advisory provides details on the vulnerable input and processing flow through ENABLED_TOOLS, TOOLSETS, tools/list, tools/call, and _call_tool_mcp. The issue is fixed in version 0.22.0. However, specific details about exploitation, impact, and affected versions require verification from official sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77243 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77243
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77243 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77243
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/pull/1448
[email protected] - Issue Tracking, Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-3r68-hf9h-887v
[email protected] - Exploit, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.