CVE-2026-77249: MCP Atlassian: Incomplete fix for CVE-2026-27826: redirect-based SSRF via unhooked requests session in Jira user-permission lookup

Published Sep 22, 2026
·
Updated

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, JiraUserMixin.lookupuserbypermissions uses the module-level requests.get function instead of the fetcher's protected session. A caller-controlled public Jira URL can redirect that unhooked request to an internal address, bypassing the redirect checks added for CVE-2026-27826. The advisory traces the vulnerable input and processing flow through JiraUserMixin.lookupuserbypermissions, requests.get, self.jira.session.get, and makessrfsafehook, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

Affected Software

2 affected componentsFixes available
MCP Atlassian MCP Atlassian<0.22.0
pip/mcp-atlassian<0.22.0
0.22.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MCP Atlassian to a version that resolves this vulnerability.

    Fixed in 0.22.0

Event History

Sep 22, 2026
CVE Published
via MITRE·06:47 PM
Data Sourced
via MITRE·06:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·08:36 PM
Data Sourced
via GitHub·08:36 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are affected?

MCP Atlassian deployments running a version prior to 0.22.0 are affected where Jira user-permission lookup can process a caller-controlled public Jira URL.

2

What does an attacker need to exploit this issue?

An attacker needs to supply or control a public Jira URL that redirects to an internal address. The vulnerable permission-lookup path follows that redirect through an unprotected module-level requests.get call.

3

Are existing SSRF redirect protections sufficient?

No. The affected lookup path does not use the fetcher's protected session, so it bypasses the redirect checks implemented in _make_ssrf_safe_hook for the earlier issue.

4

How can this be remediated?

Upgrade MCP Atlassian to version 0.22.0, which fixes the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203