PatchSiren cyber security CVE debrief
CVE-2026-77268 sooperset CVE debrief
CVE-2026-77268 MCP Atlassian OAuth fallback token directory and JSON file created without explicit owner-only modes, allowing local users or processes to read access and refresh tokens and reuse the associated Atlassian session. System administrators and security teams should review local access controls and token management practices, and update to version 0.22.0 or later. This issue affects MCP Atlassian server for Atlassian products, including Confluence and Jira, with a medium severity CVSS score of 5.5.
- Vendor
- sooperset
- Product
- mcp-atlassian
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-09-29
Who should care
System administrators and security teams responsible for local access control and token management in MCP Atlassian environments should review and update their practices to prevent unauthorized token reuse and ensure secure storage and handling of tokens. This includes verifying local access controls, reviewing token management practices, and updating to version 0.22.0 or later.
Why it matters
CVE-2026-77268 is a medium-severity vulnerability in MCP Atlassian that allows local users or processes to read access and refresh tokens and reuse the associated Atlassian session. System administrators and security teams should review local access controls and token management practices, and update to version 0.22.0 or later.
- Local access control review and remediation are required to prevent unauthorized token reuse.
- Token management practices should be verified to ensure secure storage and handling.
- Update to version 0.22.0 or later to fix the vulnerability.
Technical summary
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth fallback token directory and JSON file are created without explicit owner-only modes. Local users or processes with access through the resulting group or world permission bits can read access and refresh tokens and reuse the associated Atlassian session. The advisory provides details on the vulnerable input and processing flow through ~/.mcp-atlassian, oauth-<client_id>.json, access_token, and refresh_token.
Defensive priority
Medium priority for local access control review and token management
Recommended defensive actions
- Review local access controls and permissions for MCP Atlassian
- Verify token management and storage practices
- Update to version 0.22.0 or later
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The advisory traces the vulnerable input and processing flow through ~/.mcp-atlassian, oauth-<client_id>.json, access_token, and refresh_token. Local users or processes with access through the resulting group or world permission bits can read access and refresh tokens and reuse the associated Atlassian session.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77268 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77268
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77268 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77268
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/pull/1448
[email protected] - Issue Tracking, Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-4596-2p6p-28cv
[email protected] - Exploit, Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.