PatchSiren cyber security CVE debrief
CVE-2026-77249 sooperset CVE debrief
A vulnerability in MCP Atlassian, a Model Context Protocol (MCP) server for Atlassian products, allows an attacker to bypass redirect checks and potentially access internal addresses. The issue, fixed in version 0.22.0, arises from the use of the module-level requests.get function instead of the fetcher's protected session in JiraUserMixin._lookup_user_by_permissions.
- Vendor
- sooperset
- Product
- mcp-atlassian
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-09-29
Who should care
Defenders responsible for MCP Atlassian instances, particularly those exposed to internal addresses, should assess their exposure and apply the patch to version 0.22.0. This includes operators managing MCP Atlassian instances, platform administrators, vulnerability management teams, and security teams responsible for monitoring and mitigating potential threats.
Why it matters
Defenders should prioritize verifying their inventory of MCP Atlassian instances, assessing exposure to internal addresses, and applying the patch to version 0.22.0 to prevent potential SSRF attacks and bypass of redirect checks.
- Potential SSRF attacks on internal addresses
- Bypass of redirect checks added for CVE-2026-27826
- Verification of inventory and exposure to internal addresses
- Patching to version 0.22.0 to fix the vulnerability
Technical summary
The MCP Atlassian server for Atlassian products uses the module-level requests.get function instead of the fetcher's protected session in JiraUserMixin._lookup_user_by_permissions, allowing a caller-controlled public Jira URL to redirect the unhooked request to an internal address. This issue arises from the use of the module-level requests.get function, which does not have the same level of protection as the fetcher's session. As a result, an attacker could potentially bypass redirect checks and access internal addresses. The issue is fixed in version 0.22.0, which modifies the affected code to use the fetcher's protected session.
Defensive priority
Defenders should prioritize verifying their inventory of MCP Atlassian instances, assessing exposure to internal addresses, and applying the patch to version 0.22.0.
Recommended defensive actions
- Verify inventory of MCP Atlassian instances
- Assess exposure to internal addresses
- Apply patch to version 0.22.0
- Monitor for potential SSRF attacks
- Review compensating controls for exposed systems
- Track exceptions and retest remediated assets
- Check relevant monitoring, detection, and logs
Evidence notes
The advisory provides details on the vulnerable input and processing flow through JiraUserMixin._lookup_user_by_permissions, requests.get, self.jira._session.get, and _make_ssrf_safe_hook. The issue is fixed in version 0.22.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77249 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77249
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77249 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77249
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/pull/1448
[email protected] - Issue Tracking, Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-v9m3-wfh8-5646
[email protected] - Exploit, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.