PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77249 sooperset CVE debrief

A vulnerability in MCP Atlassian, a Model Context Protocol (MCP) server for Atlassian products, allows an attacker to bypass redirect checks and potentially access internal addresses. The issue, fixed in version 0.22.0, arises from the use of the module-level requests.get function instead of the fetcher's protected session in JiraUserMixin._lookup_user_by_permissions.

Vendor
sooperset
Product
mcp-atlassian
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-22
Original CVE updated
2026-09-29
Advisory published
2026-09-22
Advisory updated
2026-09-29

Who should care

Defenders responsible for MCP Atlassian instances, particularly those exposed to internal addresses, should assess their exposure and apply the patch to version 0.22.0. This includes operators managing MCP Atlassian instances, platform administrators, vulnerability management teams, and security teams responsible for monitoring and mitigating potential threats.

Why it matters

Defenders should prioritize verifying their inventory of MCP Atlassian instances, assessing exposure to internal addresses, and applying the patch to version 0.22.0 to prevent potential SSRF attacks and bypass of redirect checks.

  • Potential SSRF attacks on internal addresses
  • Bypass of redirect checks added for CVE-2026-27826
  • Verification of inventory and exposure to internal addresses
  • Patching to version 0.22.0 to fix the vulnerability

Technical summary

The MCP Atlassian server for Atlassian products uses the module-level requests.get function instead of the fetcher's protected session in JiraUserMixin._lookup_user_by_permissions, allowing a caller-controlled public Jira URL to redirect the unhooked request to an internal address. This issue arises from the use of the module-level requests.get function, which does not have the same level of protection as the fetcher's session. As a result, an attacker could potentially bypass redirect checks and access internal addresses. The issue is fixed in version 0.22.0, which modifies the affected code to use the fetcher's protected session.

Defensive priority

Defenders should prioritize verifying their inventory of MCP Atlassian instances, assessing exposure to internal addresses, and applying the patch to version 0.22.0.

Recommended defensive actions

  • Verify inventory of MCP Atlassian instances
  • Assess exposure to internal addresses
  • Apply patch to version 0.22.0
  • Monitor for potential SSRF attacks
  • Review compensating controls for exposed systems
  • Track exceptions and retest remediated assets
  • Check relevant monitoring, detection, and logs

Evidence notes

The advisory provides details on the vulnerable input and processing flow through JiraUserMixin._lookup_user_by_permissions, requests.get, self.jira._session.get, and _make_ssrf_safe_hook. The issue is fixed in version 0.22.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77249 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77249

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77249 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77249

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.