PatchSiren cyber security CVE debrief
CVE-2026-77254 sooperset CVE debrief
A critical vulnerability in MCP Atlassian, a Model Context Protocol (MCP) server for Atlassian products, allows unauthenticated network callers to perform operations with the operator account's permissions. This issue, fixed in version 0.22.0, enables attackers to bypass authentication and leverage globally configured Jira or Confluence credentials.
- Vendor
- sooperset
- Product
- mcp-atlassian
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-09-28
Who should care
Atlassian administrators, security teams, and IT professionals responsible for MCP Atlassian deployments should assess exposure and apply the patch. This includes operators, platform administrators, vulnerability management teams, and security teams who need to review authentication configurations and monitor for suspicious activity.
Why it matters
CVE-2026-77254 is a critical authentication bypass vulnerability in MCP Atlassian that allows unauthenticated network callers to perform operations with elevated permissions. Defenders should prioritize patching to 0.22.0 and review authentication configurations to mitigate potential risks.
- Potential unauthorized access to sensitive data
- Possible elevation of privileges for attackers
- Risk of lateral movement within Atlassian environments
- Need for urgent patching and verification
Technical summary
MCP Atlassian, a Model Context Protocol (MCP) server for Atlassian products, is vulnerable to an authentication bypass issue. Prior to version 0.22.0, requests to the HTTP MCP endpoint without a per-user identity can reach tool handlers, which then use globally configured Jira or Confluence credentials. This allows network callers to perform operations with the operator account's permissions unless there is an independent authentication boundary.
Defensive priority
High priority for Atlassian administrators and security teams to verify and apply the patch.
Recommended defensive actions
- Verify MCP Atlassian version and apply patch to 0.22.0 if vulnerable
- Review and update authentication configurations for MCP Atlassian
- Monitor for suspicious activity on MCP Atlassian instances
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
Evidence notes
The advisory provides details on the vulnerable input and processing flow through streamable-http, UserTokenMiddleware, _get_fetcher, and global credentials. The issue is fixed in version 0.22.0. Evidence from the CVE Program and NIST NVD detail page confirms the vulnerability. Defenders should verify affected scope, review authentication configurations, and monitor for suspicious activity. The patch is available in version 0.22.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77254 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77254
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77254 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77254
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/pull/1448
[email protected] - Issue Tracking, Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-vc8m-84rp-53hx
[email protected] - Exploit, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.