CVE-2026-77243
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/09/2026
Last modified:
23/09/2026
Description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, ENABLED_TOOLS and TOOLSETS are applied when tools are listed but are not rechecked when a tools/call request is dispatched. A client that knows a hidden tool name can directly invoke excluded read, write, or delete tools despite the operator's configured least-privilege restrictions. The advisory traces the vulnerable input and processing flow through ENABLED_TOOLS, TOOLSETS, tools/list, tools/call, and _call_tool_mcp, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460
- https://github.com/sooperset/mcp-atlassian/pull/1448
- https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0
- https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-3r68-hf9h-887v
- https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-3r68-hf9h-887v


