PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77250 sooperset CVE debrief

CVE-2026-77250 MCP Atlassian OAuthConfig Token Exposure. The vulnerability exists in MCP Atlassian's OAuthConfig, which writes plaintext fallback files containing access and refresh tokens under the user's .mcp-atlassian directory with process-default permissions. On systems with a permissive umask, local users and processes can read these tokens, potentially leading to unauthorized Atlassian access. System administrators and security teams should assess exposure and verify token storage and directory permissions. The issue is fixed in version 0.22.0.

Vendor
sooperset
Product
mcp-atlassian
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-22
Original CVE updated
2026-09-29
Advisory published
2026-09-22
Advisory updated
2026-09-29

Who should care

System administrators and security teams responsible for MCP Atlassian installations, particularly those with multi-user systems or permissive umasks, should assess exposure and verify token storage and directory permissions.

Why it matters

CVE-2026-77250 exposes MCP Atlassian to local token exposure. Defenders should verify and update to prevent unauthorized access.

  • Local users may access sensitive Atlassian tokens
  • Token reuse could lead to unauthorized Atlassian access
  • Requires verification of .mcp-atlassian directory permissions
  • Update to version 0.22.0 or later to fix the issue

Technical summary

MCP Atlassian's OAuthConfig writes plaintext fallback files containing access and refresh tokens under the user's .mcp-atlassian directory using process-default permissions. This can allow same-group or other local users and processes to read the persisted tokens and reuse the associated Atlassian access on systems with a permissive umask. The advisory details a vulnerability in MCP Atlassian's OAuthConfig, which writes these tokens without proper access controls, potentially exposing them to local users and processes.

Defensive priority

Medium

Recommended defensive actions

  • Review and update MCP Atlassian to version 0.22.0 or later
  • Verify .mcp-atlassian directory permissions and token storage
  • Monitor for suspicious activity related to Atlassian access
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The advisory details a vulnerability in MCP Atlassian's OAuthConfig, which writes plaintext fallback files containing access and refresh tokens under the user's .mcp-atlassian directory with process-default permissions. On systems with a permissive umask, local users and processes can read these tokens.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77250 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77250

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77250 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77250

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.